Exploitation Summary
EIP tracks 3 public exploits for CVE-2006-0731. PoCs published by Leandro Meiners.
AI-analyzed exploit summary The exploit describes a file-access/deletion vulnerability in SAP Business Connector due to an access-validation error. An attacker can disclose sensitive information or delete arbitrary files via a crafted HTTP request.
Description
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
Exploits (3)
The exploit describes a file-access/deletion vulnerability in SAP Business Connector due to an access-validation error. An attacker can disclose sensitive information or delete arbitrary files via a crafted HTTP request.
The exploit demonstrates a file-access/deletion vulnerability in SAP Business Connector due to an access-validation error. It allows an attacker to read arbitrary files (e.g., /etc/passwd) via a crafted URL request.
The provided code is a writeup describing an input-validation vulnerability in SAP Business Connector, allowing phishing attacks via crafted URIs. It includes an example URI demonstrating the issue but lacks executable exploit code.