Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data.
http://www.securityfocus.com/bid/14625
http://securitytracker.com/id?1014799