added a sql injection vulnerability
This commit is contained in:
@@ -23,7 +23,8 @@ class UsersController < ApplicationController
|
|||||||
end
|
end
|
||||||
|
|
||||||
def account_settings
|
def account_settings
|
||||||
@user = current_user
|
#@user = current_user
|
||||||
|
@user = User.find(:first, :conditions => "user_id = '#{params[:user_id]}'")
|
||||||
end
|
end
|
||||||
|
|
||||||
def update
|
def update
|
||||||
|
|||||||
Reference in New Issue
Block a user