CVE-2000-0109

Standard and Poor's ComStock - Info Disclosure

Title source: llm
STIX 2.1

Description

The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.

Exploits (1)

exploitdb WRITEUP VERIFIED
by kadokev · textlocalunix
https://www.exploit-db.com/exploits/19823

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0109

Scores

EPSS 0.0218
EPSS Percentile 84.5%

Details

Status published
Products (1)
comstock/multicsp 4.2
Published Jan 31, 2000
Tracked Since Feb 18, 2026