Decoding Latent Attack Surfaces in LLMs: Prompt Injection via HTML in Web Summarization