Trac CSRF exploit

The iframe below links to a page that submits a remote form on the targeted trac web site. This is a Cross Site Request Forgery attack.

If you were logged into the targeted web site, and your browser executes the javascript in the onload of the targeted iframe, it will cause you (as your authenticated account) to post a note to the relevant ticket saying I got burned by this exploit., elevating the priority to high, severity to critical, and adding the security keyword if none exists already.

Things to note about this exploit:

How could this be avoided? Trac Developers, thank you for your great work! If i can help you resolve this bug in any way, please let me know. I wish i was more of a python guru...

You can contact me about this exploit at dkg-trac (at) fifthhorseman.net, or at the ticket i filed about this on trac's own trac installation.

More details about CSRF attacks: