Please take this as constructive criticism, but the way you presented this is absolutely fucking useless. You're not inserting them into columns, or anything that would make them persistent. Nobody is going to click on that long of a url without questioning your intentions. Don't misunderstand me, what you have is good; however, it is completely useless without inserting it into the database.
Additionally, you could have stated *WHY* somebody would want to inject xss over SQL. One example I can think of would be injecting javascript for a drive-by download or client-side exploit/malicious iframe/beef hook. Step your game up son!