Systematically test authorized targets for SQL, XSS, SSTI, XXE, command, and request-smuggling injection classes.