SQL injection with filter bypass via XML encoding