Description
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Remediation
References
Related Vulnerabilities
PHP CVE-2009-3559 Vulnerability (CVE-2009-3559)
WordPress Plugin bodi0`s Bots visits counter Cross-Site Scripting (0.8.1)
phpBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-7143)
WordPress Plugin WordPress Download Manager Open Redirect (2.9.50)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2891)