Description
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Remediation
References
Related Vulnerabilities
Jenkins CVE-2014-2063 Vulnerability (CVE-2014-2063)
WordPress Plugin Media Library Assistant PHP Object Injection (2.60)
Oracle JRE CVE-2013-1479 Vulnerability (CVE-2013-1479)
WordPress Plugin Genesis Simple Share Cross-Site Scripting (1.0.6)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (0.9.2)