PT-2006-5354 · Mozilla · Firefox

Maddin

·

Published

2006-09-06

·

Updated

2024-02-14

·

CVE-2006-4561

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox version 1.5.0.6
Description The issue allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server. This can be achieved by hosting a script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control. The script can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
Recommendations For Mozilla Firefox version 1.5.0.6, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to potentially vulnerable intranet web servers to minimize the risk of exploitation.

Exploit

Related Identifiers

CVE-2006-4561

Affected Products

Firefox