Well, a while ago I saw this code (on my own project!):
window.open("?controller=users&action=changePassword&name=" + user_name + "&password=" + password)
I was horrified, glad it isn't live yet, and I fixed it immediately. But I'm still wondering whether I was so sleep-deprived or drunk when I wrote this. It's over SSL, so it should not be that big deal, but still, GET shouldn't be used for such things.