This post is nothing new but it's worth reading if you're a Rails dev because it highlights a uniquely Railsy security flaw, which is the default-allow accessibility of model attributes, which is made worse by the fact that ActiveRecord hides the schema (and therefore the attribute file) from the class definition where you override accessibility.
By default, all attributes should have been inaccessible to ActiveRecord::Base#new and ActiveRecord::Base#update. That was a design-level mistake.