Appearance
talk about functions like download.php?id=123.php
talk about null byte, directory traversal
IDOR and SQLis can lead to this