PT-2006-5354 · Mozilla · Firefox
Maddin
·
Published
2006-09-06
·
Updated
2024-02-14
·
CVE-2006-4561
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox version 1.5.0.6
Description
The issue allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server. This can be achieved by hosting a script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control. The script can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
Recommendations
For Mozilla Firefox version 1.5.0.6, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to potentially vulnerable intranet web servers to minimize the risk of exploitation.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox