A-11 XPath 注入

故意设计的安全漏洞

🔍 XML 用户查询

💡 XPath 注入提示

绕过: username=' or '1'='1 提取: username=' or contains(secret,'FLAG') or '1'='2