Mozilla · Firefox · CVE-2006-4561
**Name of the Vulnerable Software and Affected Versions**
Mozilla Firefox version 1.5.0.6
**Description**
The issue allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server. This can be achieved by hosting a script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control. The script can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
**Recommendations**
For Mozilla Firefox version 1.5.0.6, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to potentially vulnerable intranet web servers to minimize the risk of exploitation.