vendredi 18 août 2017

CSV injection msexcel?

I know what is the CSV injection, luckily i have a website which is the export functionality of csv file so i am trying to exploit the csv injection,

So i tried a basic payload i.e.=SUM(10+10) and it works, but that's not enough for me so i read more and found another payload i.e. =cmd|' /C calc'!A0 but it didn't work, now

Whats the problem? I can't able to open up the calculator, i dont know why, Is there any update version of the msexcel? thats why it didn't work

Can anyone please suggest me.

Thank you




Aucun commentaire:

Enregistrer un commentaire