Web Hack List

Other nomination

The Absurdly Underestimated Dangers of CSV Injection

A cell that an ordinary user plants in an application, beginning with an equals, plus, minus or at sign, is evaluated as a formula when an administrator opens the CSV export. Excel DDE payloads run commands on the administrator machine, and a Google Sheets IMPORTXML formula silently posts their rows, and other spreadsheets they can read, to the attacker server.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.