Pwnie Awards 2017

The 2011 Pwnie Award For Best Server-Side Bug

CVE-2010-3332

Juliano Rizzo, Thai Duong

Juliano and Thai showed that the ASP.NET framework is vulnerable to a padding oracle attack that can be used to remotely compromise almost any ASP.NET web application, often leading to remote code execution on the server.