Makes me consider to start always casting URL query parameters as a defensive measure, regardless of this specific vulnerability being patched.
e.g. if you have the code:
$collection->findOne( array( 'username' => $_POST['username'], 'password' => $_POST['password'] ) );
someone could POST something like username[$ne]='?'&password[$ne]='?' and login.params[:id] could be a string, integer, hash, or array when accessed in the controller actions.
If only there were some kind of concept of typing, perhaps enforced by the language and statically applied, which would eliminate this class of error entirely...boy, that would be helpful in larger systems.