Comment Re:We've already seen this before (Score 1) 170
ICEfaces uses XML for encoding page updates, so is not vulnerable to JavaScript hijacking, but including the icefacesID along with XMLHttpRequest POST data is necessary to prevent cross site request forgery.