Run the brakeman command from the root of your rails application
brakeman
app/controllers/posts_controller.rb
def show
message = params[:message] || 'hello world'
eval("echo '#{message}'")
end
app/controllers/home_controller.rb
class HomeController < ApplicationController
def index
xmen_or_avengers = params[:xmen_or_avengers] || 'xmen'
puts send(xmen_or_avengers.to_sym)
end
private
def xmen
'Wolverine'
end
def avengers
'Captain America'
end
end