This post introduces Formula Injection, a technique for exploiting ‘Export to Spreadsheet’ functionality in web applications to attack users and steal spreadsheet contents. It also details a command injection exploit for Apache OpenOffice and LibreOffice that can be delivered using this technique.
more here...............http://contextis.co.uk/blog/comma-separated-vulnerabilities/
more here...............http://contextis.co.uk/blog/comma-separated-vulnerabilities/