The dns poisoning /w man in the middle would only allow a sql injection if the easy populate script didn't sanitize the csv.