How can I prevent XPATH injection in the .NET Framework?
We were previously using string concatenation to build XPATH statements, but found that end users could exec
Strongly typed parameters are available if you use a full-blown XsltTransform.