Some details on how this can be exploited:
http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-ma...
http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-ma...
<3<3<3<3
With love :-) Thomas
i just tried quoted_id and it works against mysql on 3.2.x as well. quoted_id is defined in abstract/quoting.rb and any adapter that forwards quotes to the superclass will use it.