Rails' Insecure Defaults

Cross-Site Scripting (XSS)