OWASP / railsgoat

A vulnerable version of Rails that follows the OWASP Top 10
railsgoat.cktricky.com
MIT License
857 stars 663 forks source link

Metaprogramming section - ouch #169

Open cktricky opened 9 years ago

cktricky commented 9 years ago

Yeah, so, I confuse ppl and don't really show the problem well or the fix w/ regards to the actual problems associated with constantize. Dir traversal is mixed in w/ that issue.

Additionally, the send() method isn't even filled out.

cktricky commented 6 years ago

I should probably do this as it was pointed out to me this issue is over 3 years old sooooo... bump to myself? idk