Ilia has written a very good article about CSRF and XSS attacks, how they work and how to prevent them for ez.no.