class TutorialsController < ApplicationController skip_before_filter :has_info skip_before_filter :authenticated def index end def show render "injection" end def injection end def xss @code = %{
| Full Name | Income | Bonuses | Years w/ MetaCorp | SSN | DoB |
|---|---|---|---|---|---|
| <%= "#{@user.first_name} #{@user.last_name}" %> | <%= @user.work_info.income %> | <%= @user.work_info.bonuses %> | <%= @user.work_info.years_worked %> | <%= @user.work_info.SSN %> | <%= @user.work_info.DoB %> |