Every other web stack has this problem in one form or another; for instance, in J2EE, which is either the first or second best-secured web stack out there, you can bypass the best-known best-documented access controls by changing your HTTP verb from "GET" to "SUPERGET", "GETX", or "GIMME".
But Rails kind of went out of its way to win this particular vulnerability, and so now it's something you have to audit for on every project.