Sorry.. I probably seem like I'm doing this for the karma. I'm not; I just wanted to see if a flaw existed. It does.. The upvote needs to be a POST, not a GET.
Shawn Presser
Shawn Presser
To protect a site, you must include an unguessable parameter in all side-effecting requests.
And if you're going to be putting the session id somewhere, it should be in a POST request, not a GET request, otherwise it can be hijacked.
To fix the problem, PG needs to check that the userid that clicked the fnid is the same as the userid for which it was created.
BTW, browser bugs actually make the problem even more complex than this because it is sometimes possible to steal content off of other pages.
"If you use GET for interactions with side-effects, your make your system insecure."
(from http://www.w3.org/2001/tag/doc/whenToUseGet.html#safe)