Assume that you are viewing a blog web site in your browser, which might contain malicious scripts. At the same time, you logged in to your account at hubbm.com web site in another tab of your browser. hubbm.com web site does not use cookies and embed session IDs as a parameter to every generated HTML page. Is it possible that the blog page can launch a CSRF attack on hubbm.com web page?