HomeSecurityCross-site scripting (XSS) on the official Digea website

Cross-site scripting (XSS) on the official Digea page

Digea Digital Provider S.A. is a company established by the private national television channels ALPHA, ALTER, ANTENNA, MAKEDONIA TV, MEGA, SKAI and STAR.
On February 7, 2014, it was declared the winner of the tender for the entire set of radio frequency usage rights for national and regional coverage. The company's objective was to build the country's digital terrestrial network and complete the transition from analog to digital television signal.Digea

By the end of 2013, the company activated 13 broadcast centers across Greece, giving access to the free terrestrial digital television signal to over 70% of the country's population.

With the completion of the terrestrial digital transition, 156 broadcasting centers were activated, covering 95% of the Greek population with a digital signal.

The company's achievements are truly impressive, but according to our well-known researcher Nyo(GHS), Digea's official website allows malicious or non-malicious users to use Cross-site scripting or XSS.

Cross-site scripting or XSS refers to the exploitation of various vulnerabilities in computer systems by inserting HTML or Javascript code into a web page. A malicious user could inject code into a web page, for example through input text, which, since it would not be filtered by the page correctly, could cause problems for the site administrator or visitor.

Example:

https://www.example.com/index.html?name=

The malicious user could:

Steal account passwords and personal data
Change website settings
Steal cookies
Upload false advertisements, via a link

Vulnerability refers to the system's inability to filter and reject any harmful inputs.

See the screenshots Nyo sent us

digea

Cross-site scripting (XSS) on the official Digea page

According to the researcher, he made the XSS public in response to the video “MEGA – DIGEA threatens with BLACK!”

The video states that “according to information, the Board of Directors of Digea has decided to proceed with weakening the station's signal despite the fact that negotiations are underway between shareholders and banks to find a solution. This means that either a “broken” image with pixels will be displayed, or a “frozen” image and only sound will be heard.”

https://www.youtube.com/watch?v=FCw3mzqefjg

He also states that the disclosure of XSS was not made to support a private channel but the end user-viewer.
XSS affects the entire page through javascript and can completely distort it.Cross-site scripting (XSS) on the official Digea page

SecNews.gr is available to anyone interested by the management team of the Digea.gr page for details of the vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS