CVE-2000-0109 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 8.4% (pctl 95)
Patch early
A public exploit exists.
Description
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 8.42% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-01-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| comstock | multicsp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Standard & Poors ComStock 4.2.4 - Command Execution | 2000-03-24 |
References
→ the Explorer · watch your stack · NVD