It is recommended that any request parameter by which destination page is to be derived be a mapping value, rather than the actual URL or portion of the URL. This can prevent from:
Injection
Cross Site Request Forgery
Unvalidated Redirects and Forwards
Failure to Restrict URL Access