The following are a number of additional reading resources:
- Vulnerable components: https://resources.infosecinstitute.com/exploring-commonly-used-yet-vulnerable-components/
- Testing for insecure direct object references: https://www.owasp.org/index.php/Testing_for_Insecure_Direct_Object_References_(OTG-AUTHZ-004)
- Web server misconfiguration: https://www.owasp.org/index.php/Top_10-2017_A6-Security_Misconfiguration