...But Doesn't Rails Take Care of Security for Me?

Cross-Site Scripting (XSS)