From CVS import to cmd.exe – via SQL injection