CSRF(Cross-site request forgery)
CSRF(Cross-site request forgery),中文名称:跨站请求伪造,也被称为:one click attack/session riding,缩写为:CSRF/XSRF
http://www.cnblogs.com/hyddd/archive/2009/04/09/1432744.html
http://www.freebuf.com/articles/web/55965.html
SQL注入