This fixes a security vulnerability in rails, permitting the evaluation of Ruby code through a URL. for details, see http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure
Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn't require a browser. from msf