Prevent argument injection in `exiftool`

We're using exiftool with Popen, thus making us vulnerable to argument injection. We can't simply blacklist files starting with a dash (-) because that's kind of legitimate.