Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBcode tag.Referenceshttp://secunia.com/advisories/23431http://www.vupen.com/english/advisories/2006/5115http://www.securityfocus.com/archive/1/454868/100/0/threaded