xpath injection vulnerabilities and exploits