Spoofing Vulnerability in SAP Business Connector Core
CVE-2006-0731
Currently unrated
What is CVE-2006-0731?
The SAP Business Connector Core contains a vulnerability that allows remote attackers to conduct spoofing attacks. Specifically, the issue lies in the WmRoot/adapter-index.dsp component, where an attacker can exploit the url parameter to insert an absolute URL. This enables attackers to load untrusted external sites within a frame, potentially leading users to believe they are interacting with legitimate content. Users of affected versions should take precautions to mitigate the risk of phishing and other malicious activities.