Yes XSS on the official page of the ruling party. Following our announcement of the new facility Secleaks offered by SecNews.gr, λάβαμε μια ειδοποίηση που αξίζει να δημοσιεύσουμε. Αποστολέας της ευπάθειας (όπως θα δείτε και στην πρώτη εικόνα) είναι ο Nyo από την team Greek Hacking Scene (GHS).
We also have the vulnerability links available to any interested manager who wants to resolve the issue.
See the images that show the vulnerability:
For those who do not know:
By the term Cross-site scripting or XSS we refer to the exploitation of various vulnerabilities of computer systems withtreatment HTML or Javascript code on a site. A malicious user could inject code into a website, through an input text for example, which since it would not be filtered by the website properly, could cause problems for the administrator or visitor of the target website.
Example:
http://www.example.com/index.html?name=
The malicious user could succeed:
Theft of passwords / accounts etc of personal data
Change website settings
Theft of cookies
Fake advertising (via, for example, a link)
Vulnerability refers to the weakness of the system that supports the webspace to filter and reject any harmful inputs.
SecNews.gr remains at the disposal of anyone interested in it resolution of the problem.
Definition of XSS from Wikipedia.