Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > MISCELLANEOUS > Archives > Bug Report 1.4.x

Post Reply
 
Thread Tools
  #1  
Old 08-27-2005, 01:04 PM
sapphirecat Offline
forum loafer
 
Join Date: Apr 2005
Location: KJHW
Posts: 7
XSS in EXIF data?

Cedric Cochin recently posted to the BugTraq mailing list about the possibility of cross-site scripting (XSS) by uploading an image with malicious EXIF data embedded to various PHP image galleries. Basically, the attack is to replace an ASCII field in the EXIF data that is displayed on the page with some HTML/Javascript, which will then run in the browser of a visitor when the image and its EXIF data are displayed.

This could probably be fixed by using htmlspecialchars() or something when putting the EXIF tags into the template. Since only the admin/owner can upload images to Pixelpost, I don't think there's any risk of actual attack, but if it is fixed then we make sure of that.
__________________
......:: sapphirecat
Reply With Quote
  #2  
Old 08-27-2005, 05:18 PM
Joe[y]'s Avatar
Joe[y]+ Offline
Team Pixelpost
 
Join Date: Mar 2005
Location: UK
Posts: 3,101
Send a message via MSN to Joe[y]
as you mention this isn't an immediate threat and i wouldn't necessarily class it as a bug. but of course, it's an improvement - no reason to say no to that. i'll mention it for our development version. cheers!
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 01:21 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs