Do not use default GET actions unless absolutely necessary. For example, if you have a DeleteUser action that does not have [AcceptVerbs(HttpVerbs.Post)] , it can be called via
<img src="http://yoursite/admin/DeleteUser/1" />
which will be called by someone else βdisplaysβ the image.
swilliams
source share