Quote from changes.txtr884 | Gizmore | 2009-03-26 02:06:19 +0100 (Thu, 26 Mar 2009) | 3 lines
Bound csrf tokens to $_SERVER['SCRIPT_NAME']
This will still allow to xss forum.php flaws to execute forum.php actions, but nothing other like account.php