CVE-2000-0109

Standard and Poor's ComStock - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0109. PoCs published by kadokev.

AI-analyzed exploit summary This is a vulnerability writeup detailing multiple security issues in ComStock, including weak/default credentials and privilege escalation via the 'more' command. It also mentions the potential for RedHat 5.1 exploits to compromise the system.

Description

The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.

Exploits (1)

exploitdb WRITEUP VERIFIED
by kadokev · textlocalunix
https://www.exploit-db.com/exploits/19823

This is a vulnerability writeup detailing multiple security issues in ComStock, including weak/default credentials and privilege escalation via the 'more' command. It also mentions the potential for RedHat 5.1 exploits to compromise the system.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ComStock (based on RedHat 5.1)
No auth needed
Prerequisites: network access to the ComStock machine · knowledge of default credentials
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0109

Scores

EPSS 0.0842
EPSS Percentile 94.4%

Details

Status published
Products (1)
comstock/multicsp 4.2
Published Jan 31, 2000
Tracked Since Feb 18, 2026