Web Hack List

Collected research

The Absurdly Underestimated Dangers of CSV Injection

A cell that an ordinary user plants in an application, beginning with an equals, plus, minus or at sign, is evaluated as a formula when an administrator opens the CSV export. Excel DDE payloads run commands on the administrator machine, and a Google Sheets IMPORTXML formula silently posts their rows, and other spreadsheets they can read, to the attacker server.

Record

Published by
georgemauer.net
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of georgemauer.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .