tag:blogger.com,1999:blog-8503755746105415394.post-22436501287633721752008-03-21T10:03:00.000Z2008-03-21T10:03:00.000Z@ted - Well, we may or may not know (or be able to...@ted - Well, we may or may not know (or be able to deduce) the table structure in either case. But the point is that, other things being equal, the XSRF vector applies to both vulnerablities, and so they should be assigned the same threat rating.PortSwiggerhttp://www.blogger.com/profile/04744809054520271899noreply@blogger.com