http://stackoverflow.com/questions/698700/escaping-html-in-r...
Correct me if I am wrong but it seems to me that RoR still isn't shipped with a safe default?
Edit: RoR added auto-escaping around February 2010, Django had it since November 2007
http://yehudakatz.com/2010/02/01/safebuffers-and-rails-3-0/ https://code.djangoproject.com/wiki/AutoEscaping?x=52&y=...
Prior before that, the standard way to sanitize html output was to write <%= h foo %> instead of <%= foo %> in your templates.
And as of late tons of similar bugs have been found. CSRF and database parameterization was well known issues when Rails was written, so yeah props for that. It is just not enough anymore.