PA's security advisory stance needs fixing. PANOS less that 5.0.9 contains XSRF and I just happened to stumble on this, on an unrelated site
I just stumbled on this security advisory while I was googling something totally unrelated...
http://packetstormsecurity.com/files/124184/panp-xssxsrf.txt
"These issues have been fixed in PANOS 5.0.9, mentioned in the release notes like this:
57343—Fixe
...