Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2020-16270 | Kitploit
Tools/GitHubGitHub/security-avs/cve-2020-16270
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPhishingPenetration Testing
GitHubsecurity-avs/cve-2020-16270

CVE-2020-16270

View Repository
5 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020-16270

[Suggested description]: OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS.
Remote Attacker can use discovered vulnerability to inject malicious JavaScript payload to victim’s browsers in context of vulnerable applications. Executed code can be used to steal administrator’s cookies, influence HTML content of targeted application and perform phishing-related attacks. Vulnerable application used in more than 3000 organizations in different sectors from retail to industries.
[Additional Information]:
A letter was sent to the vendor about the vulnerability. Vulnerability was confirmed by vendor.
Vulnerability was confirmed by government agency: https://bdu.fstec.ru/vul/2020-04623
[Vulnerability Type]: Cross Site Scripting (XSS)
[Vendor of Product]: olimpoks.ru
[Affected Product Code Base]: online olimpoks system under 3.3.39.
[Attack Type]: Remote
[Impact Denial of Service]: False
[Impact Information Disclosure]: True
[Attack Vectors]: Vulnerable URL and parameter: http://olimpoks.TARGET-HOST:9001/Auth/Admin?ErrorMessage=bb%27);alert(1);//
[Discovered]: Alexander Semenenko, Luka Safonov, Sergey Zelensky
[Proof of Concept]:
stack Overflow

Download Tool