I was looking for the date when RoR changed their templating so it always output sanitized content and I found this:
http://stackoverflow.com/questions/698700/escaping-html-in-r...
Correct me if I am wrong but it seems to me that RoR still isn't shipped with a safe default?
Edit: RoR added auto-escaping around February 2010, Django had it since November 2007
http://yehudakatz.com/2010/02/01/safebuffers-and-rails-3-0/ https://code.djangoproject.com/wiki/AutoEscaping?x=52&y=...