Vendor response: "This isn't an issue." Problem: the cherokee server admin configuration web interface is vulnerable to csrf. Impact: if an admin is logged into the cherokee admin interface and visits a site which runs "bad tm scripts" cherokee can be reconfigured to run as $user and set log handlers(hooks) to execute arbitrary commands (on error and on access).