it's about a XSS/frame injection attack; the javadoc generated by any
older version of the Sun/Oracle javadoc tool allows frame injection
(when the framed version is deployed) opening a door to redirecting
visiting browsers to malicious content/site.
---
Setting up a Windows 7 / JDK 6 environment for testing. I also note that you
can no longer easily navigate to download JDK 6 (sigh).
It also looks like there is a security issue on javadocs:
-
http://www.oracle.com/technetwork/java/javase/7u25-relnotes-1955741.html#jpi-upt
TLDR: Run a tool over