added fixmes for sql injection vulnerabilities

This commit is contained in:
Jonathan Kolyer 2015-08-04 14:11:46 +00:00
parent 6a806a05cb
commit c11cc5eb9e
1 changed files with 2 additions and 0 deletions

View File

@ -102,6 +102,7 @@ module JamRuby
def self.search_target_class
end
# FIXME: SQL INJECTION
def _genres(rel, query_data=json)
gids = query_data[KEY_GENRES]
unless gids.blank?
@ -112,6 +113,7 @@ module JamRuby
rel
end
# FIXME: SQL INJECTION
def _instruments(rel, query_data=json)
unless (instruments = query_data[KEY_INSTRUMENTS]).blank?
instsql = "SELECT player_id FROM musicians_instruments WHERE (("