adding render vuln

This commit is contained in:
Mike McCabe
2015-02-23 20:36:53 -05:00
parent 975002ea76
commit 1eee953f62
3 changed files with 8 additions and 3 deletions
+4 -1
View File
@@ -22,5 +22,8 @@ class DashboardController < ApplicationController
@user = current_user
render :partial => "layouts/dashboard/dashboard_stats"
end
def doc
render "../../doc/" + params[:doc]
end
end
+3 -1
View File
@@ -27,13 +27,15 @@
</div>
</div>
</div>
<center><b>Need help using this portal? Check out the <a href="doc?doc=README_FOR_APP">Readme</a></b></center>
</div> <!-- end span12 -->
</div>
</div>
</div>
<script type="text/javascript">
function makeActive(){
Executable → Regular
+1 -1
View File
@@ -6,7 +6,7 @@ Railsgoat::Application.routes.draw do
match "forgot_password" => "password_resets#forgot_password"
get "password_resets" => "password_resets#confirm_token"
post "password_resets" => "password_resets#reset_password"
get "dashboard/doc" => "dashboard#doc"
resources :sessions do
end