tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection
id: CVE-2012-5321
info:
name: TikiWiki CMS Groupware v8.3 - Open Redirect
author: ctflearner
...