The 2013 Pwnie Winner For Best Server-Side Bug

Ruby on Rails YAML (CVE-2013-0156)

Credit: Ben Murphy

While lots and lots of Ruby libraries like YAML, Ruby on Rails likes it the most. This vulnerability leads to remote SQL injection and arbitrary Ruby code execution on the server, bringing down a variety of Ruby on Rails web sites.

 (CVE-2013-0156)