diff options
author | Andreas Gohr <andi@splitbrain.org> | 2006-03-05 11:28:10 +0100 |
---|---|---|
committer | Andreas Gohr <andi@splitbrain.org> | 2006-03-05 11:28:10 +0100 |
commit | 93c020ac9b91843bbf74ce62f6f4712e31435fe1 (patch) | |
tree | bca69ee6b191df12b5c164eb65b5ef70c628b09e /lib/plugins | |
parent | 0f3058750a5c51ab212bb73db103969bf6f03953 (diff) | |
download | rpg-93c020ac9b91843bbf74ce62f6f4712e31435fe1.tar.gz rpg-93c020ac9b91843bbf74ce62f6f4712e31435fe1.tar.bz2 |
SECURITY FIX - fix for a minor XSS vulnerability in image metadata handling
Image meta data (from EXIF/IPTC fields) was not escaped correctly in the
media select popup. This allowed to introduce malicious javascript code
through EXIF tags. Only the media manager was affected.
darcs-hash:20060305102810-7ad00-7d8c7c32b914ff9d9987da5c137d01e2153d569c.gz
Diffstat (limited to 'lib/plugins')
0 files changed, 0 insertions, 0 deletions