Hackers Can Delete Facebook Friends, Thanks to Flaw
pcworld.com
pcworld.com
http://prominentsecurity.com/?p=119
It also says that the flaw has been patched:
"*Update (5/22/10): After reporting the flaw to Facebook Wednesday afternoon, I have confirmed as of Friday afternoon that the flaw has been successfully patched. Facebook now strictly enforces the existence of the “post_form_id” CSRF protection token in the request."
Django will do this for you; presumably other frameworks have similar mechanisms.