I don't think all of these examples involve embedding strings. Many people assume that they can use any ActiveRecord method, and as long as they don't embed strings, they'll be safe from sqli. Take this first example:
Order.calculate(:sum, params[:column])
I've just checked in Rails 3.2.12 and this is still possible, haven't checked against Rails 4.0. If I pass in:
http://localhost:3000/adverts/1?column=id) FROM users WHERE name = 'Bob' SUM(id;
And do a simple sum in the controller:
sum = Advert.calculate(:sum, params[:column])
# or
sum = Advert.sum(params[:column])
I get:
SELECT SUM(id) FROM users WHERE name = 'Bob' SUM(id) FROM "adverts"
Which is not good as it is injecting sql - with judicious use of sql comments etc it could probably be made to execute any sql statement (apparently it does on sqlite with this particular test, but it fails in postgresql which I tested with). Other queries work with psql though [deleted example and reported]. I've reported this with a working example of sqli just in case it is an unreported problem.
Now the intended use of sum, count etc is to deal with symbols chosen by the programmer, but a naive implementation of say an admin form for summing some record attributes might use a param from a form, and pass that in to the sum method for column name, just as they might use params[:id] with find. I think Rails should deal with that.
Also the example given of User.exists? params[:id] is probably commonly used, but vulnerable to manipulation of results at the very least.
I'm not the original author of this page (which is already public and probably has been for some time), and am aware this is not an appropriate place to report bugs, but it would be reassuring if the Rails team looked at this link and fixed anything which is dangerous like the usage above.
IMHO all rails ActiveRecord methods should guard against sqli as much as possible, not just the commonly used ones, and if they don't currently it needs to be fixed.