From a previous post, it seems to me the suggestions for DDOS'ing (as a low-bar way to exploit) converge on hitting a expensive query/operation many times and this can be aided by various tools, such as botnets and load testing tools.
What about other "common" security exploits? ie, exploits that are commonly unprotected against and can cause damage to a website?