Savy Soda Documents - Mobile Office Suite '.XLS' Denial of Service
Author: Matthew Bergin
type: dos
platform: hardware
port:
date_added: 2010-06-10
date_updated: 2017-01-24
verified: 0
codes:
tags:
aliases: savysoda_poc.xls
screenshot_url:
application_url:
I wrote a fuzzer "dumb fuzzer" and used a sample from http://www.ccp14.ac.uk/ccp/web-mirrors/bca-spreadsheets/scanplot101.xls which I randomly found on the internet. I mutated the data and tested roughly 1000 cases on several Document Reader Applications for iPhone.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/13825.xls (savysoda_poc.xls)