CVE-2006-0731
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
Date published : 2006-02-16
http://www.securityfocus.com/bid/16671
http://www.securityfocus.com/archive/1/425056/100/0/threaded