peter bassill · operator
$ cve CVE-2000-0757 JSON

CVE-2000-0757 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.1% (pctl 90)

Patch early

A public exploit exists.

Description

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.09% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2000-10-20
Last modified2026-06-16

Affected (1)

VendorProduct
aptis softwaretotalbill

Public exploits

SourceTitleDate
exploit-dbAptis Software TotalBill 3.0 - Remote Command Execution2000-08-08

References

→ the Explorer  ·  watch your stack  ·  NVD