How prevalent is Rails 3 right now?
I somehow feel that defensive programming practices would have caught this bug. There is a lot of "magic" going on that lead to this exploit.
Sending text/xml to an application shouldn't have a huge impact but when you are dynamically creating objects out of the content it can lead to some serious problems.
Python has this too with pickle. However with Python it is pretty damn obvious that pickle is NOT SAFE. You also have to import it manually.