<h1 class="page-header"><%= name %></h1>
<% include ../partials/ruleInfo.ejs %>
<% sinkData.forEach(function(sink) { %>
<div class="row">
  <div class="col-xs-12 col-sm-6" style="padding-bottom: 30px;">
    <h4 class="sub-header">
      <code><%= sink.name %></code>
    </h4>
    <form method="<%= sink.method %>" action="<%= sink.url %>/unsafe" target="_blank">
      <div class="form-group">
        <label>SELECT "${input}" as "test";</label>
        <% if(sink.name == "pg.Connection.prototype.query (String)" || sink.name == "pg.Connection.prototype.query (Object)"){ %>
          <input name="input" class="form-control" value="; DROP TABLE Students;--" />
        <% } else if(sink.name == "mysql/lib/Connection.query"){ %>
          <input name="input" class="form-control" value="SELECT SLEEP(1)--" />
        <% } else{ %>
          <input name="input" class="form-control" value="Robert&quot;); DROP TABLE Students;--" />
       <% } %>
      </div>
      <button type="submit" class="btn btn-primary">Submit</button>
    </form>
  </div>
</div>
<% }); %>
<% include ../partials/safeButtons %>
