It happens when URLs or form parameters contain references to objects such as files, directories, database records or keys.Banking Web sites commonly use a customer account number as the primary key, and may expose account numbers in the Web interface.References to database keys are frequently exposed, OWASP writes.