Description
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Remediation
References
Related Vulnerabilities
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.22)
WordPress Plugin SpamTask Arbitrary File Upload (1.3.6)
WordPress Plugin Hide My WP Cross-Site Scripting (4.53)
WordPress Plugin Gwolle Guestbook Cross-Site Scripting (2.5.3)
WordPress Plugin Hero Maps Premium Cross-Site Scripting (2.2.1)