PT-2006-5354 · Mozilla · Firefox

Maddin

·

Publicado

2006-09-06

·

Atualizado

2024-02-14

·

CVE-2006-4561

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 1.5.0.6
Description The issue allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server. This can be achieved by hosting a script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control. The script can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
Recommendations For Mozilla Firefox version 1.5.0.6, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to potentially vulnerable intranet web servers to minimize the risk of exploitation.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4561

Produtos afetados

Firefox