Ruby on Rails Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2014-0080
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3 and 4.1.0.beta1 when PostgreSQL is used allows remote attackers to execute quotadd dataquot SQL commands via vectors involving (backslash) characters that are not properly handled in operations on array columns.