Journal Journal: InfoQ: Padding Oracle Affects JSF, Ruby on Rails, ASP.NET
http://www.infoq.com/news/2010/10/Padding-Oracle
Using a Padding Oracle (PO) attack a malicious user can access encrypted data such as cookies, state, membership password, etc. According to Juliano Rizzo, the security vulnerability affects JavaServer Faces, Ruby on Rails, ASP.NET and other technologies and platforms.