PDA

View Full Version : Coppermine Photo Gallery EXIF Data Script Insertion


admin
08-23-2005, 01:24 AM
Coppermine Photo Gallery
http://coppermine-gallery.net
August 22, 2005

http://secunia.com/advisories/16499/
http://coppermine-gallery.net/forum/index.php?topic=20933.0

Description:
A vulnerability has been reported in Coppermine Photo Gallery, which can be exploited by malicious people to conduct script insertion attacks.

EXIF data stored in certain image files are not properly sanitised before being displayed to users. This can be exploited to execute arbitrary script code in a user's browser session in context of an affected site when malicious EXIF data are viewed.

The vulnerability has been reported in versions prior to 1.3.4.

Solution:
Update to version 1.3.4.

Provided and/or discovered by:
Reported by vendor.

Original Advisory:
http://coppermine-gallery.net/forum/index.php?topic=20933.0