frame spoofing using document.open() testcase

invoke an exploit