The "NoScript" Firefox plug-in can be used by clients to defend against XSS attacks. However, it can only be effective against a certain type of XSS attacks. Which type of XSS attacks is the NoScript plugin effective against and why? Why isn't it effective against other types of XSS attacks?