peter bassill · operator
$ cve CVE-2000-0109 JSON

CVE-2000-0109 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 8.4% (pctl 95)

Patch early

A public exploit exists.

Description

The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS8.42% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2000-01-31
Last modified2026-06-16

Affected (1)

VendorProduct
comstockmulticsp

Public exploits

SourceTitleDate
exploit-dbStandard & Poors ComStock 4.2.4 - Command Execution2000-03-24

References

→ the Explorer  ·  watch your stack  ·  NVD