<?xml version="1.0" encoding='utf-8'?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="card1" title="Cross-site request forgery - Page 5 - Wikipedia">
<p>
<a accesskey="1" href="page.php?w=cross-site_request_forgery&amp;p=4">1.Previous</a><br />
<a accesskey="3" href="page.php?w=cross-site_request_forgery&amp;p=6">3.Next</a>
</p>
<p>by a <a href="page.php?w=HTTP_cookie">cookie</a> saved in the user's <a href="page.php?w=web_browser">web browser</a> could unknowingly send an <a href="page.php?w=HTTP">HTTP</a> request to a site that trusts the user and thereby cause an unwanted action.</p>

<p>A general property of web browsers is that they will automatically and invisibly include any cookies (including session cookies and others) used by a given domain in any web request sent to that domain. This property is exploited by CSRF attacks. In the event that a user is tricked into</p><p>
<a accesskey="1" href="page.php?w=cross-site_request_forgery&amp;p=4">1.Previous</a><br />
<a accesskey="3" href="page.php?w=cross-site_request_forgery&amp;p=6">3.Next</a>
</p>

<do type="prev" label="Search">
        <go href="search.wml"/>
</do>

</card>
</wml>
