It would have used more than 2 colours.
It would have used consistent capitalization.
It would not have underlined everything.
It would have divided up menu options into related groups.
* http://www.cheapraybansunglassesa.com/wp-content/uploads/201...
* https://i.stack.imgur.com/8LzMo.jpg
* http://thinview.com/images/emulator.gif
* http://hunterstrainingassociates.com/images/ispf1_25.gif
* https://as400iseries.files.wordpress.com/2013/03/libraries1....
* https://seasoft.com/assets/seasoft.com/seasoft.com/public/up...
Gives a whole new meaning to critical vulnerabilities. Sheesh.
A site is vulnerable to XSRF if it doesn't use tokens when performing critical operations, critical operations are (usually) performed using HTTP POST, which can be done via form submission... token generation and validation is done server side...
You can perform a successful XSRF attack in a browser with javascript completely disabled.