This machine begins w/ a web application (flyspray 1.0) that is susceptible to XSS + CSRF on its post comments which will create an admin account for the attacker when admin visits the post causing the malicious script to reflect onto the admin’s browser. The admin account that is creat...