At DEFCON 31, JHaddix and Gunnar presented a talk titled SusParams which uncovered research on parameters which are often vulnerable to common vulnerabilities such as SQLi, SSRF, LFI, etc. This page simply breaks down the parameters observed for reference.
start
path
domain
source
url
site
view
template
page
show
val
dest
metadata
out
feed
navigation
image_host
uri
next
continue
host
window
dir
reference
filename
html
to
return
open
port
stop
validate
resturl
callback
name
data
ip
redirect