So if that is the case, whats to stop an attacker from first requesting the target form with a GET and then submitting the form with any desired values (including the freshly server-supplied and thus valid nonce) just like the user would do? Perhaps implemented as a flash banner running on the attackers site?
Hope this helps,
Daniel Papasian
---------------------------------------------------------------------------- Join us on IRC: irc.freenode.net #webappsec