A good article by Robi about the dangers of xpath injection in xml documents.
Link: Avoid the dangers of XPath injection