CVE-2008-4094 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4094): Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
http://blog.innerewut.de/2008/6/16/why-you-should-upgrade-to-rails-2-1 Patch for 2.0.2: http://blog.innerewut.de/files/rails/activerecord-2.0.2.patch
*** This bug has been marked as a duplicate of bug 237385 ***