Some Common Attack Vectors - University of Cincinnati

attacker to more improperly protected admin pages. A page provides an 'action' parameter to specify the function being invoked, and different actions require different roles. ................
................