9.3
CVSSv2

CVE-2014-3524

Published: 26/08/2014 Updated: 07/02/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 829
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Apache OpenOffice prior to 4.1.1 allows remote malicious users to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice

libreoffice libreoffice

Vendor Advisories

LibreOffice Calc could be made to crash or run programs as your login if it opened a specially crafted file ...
Apache OpenOffice before 411 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet ...

Github Repositories

CSV-Injection-validation CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files When a spreadsheet program such as Microsoft Excel or LibreOffice Calc is used to open a CSV, any cells starting with = will be interpreted by the software as a formula Maliciously crafted formulas can be used for three key attacks: Hijacking t

CSV injection Sanitizer written in Go

Sanitize your CSV to avoid CSV Injection Explanation The following CSV will execute the Formula =1+1 with the Microsoft Excel or LibreOffice Calc opening First Name,Second Name,Phone Number,Birth Year Bob,Doe,123123123,1994 Alice,Cooper,321321321,1993 PoC,CSVi,=1+1,@test To avoid this injection, is enough to add a blankspace before the

1.Explain the DOM XSS vulnerability.

SECURITY-BOAT-EXAM Q1Explain the DOM XSS vulnerability Answer : DOM XSS,known as"type-0 XSS," is a type of Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious code into a web page, but with a twist Unlike other XSS vulnerabilities where the code is sent to the server and reflected back, DOM XSS attacks happen entirely within the clie