Air Traffic Control systems that are web-app enabled. Does anyone else see a problem with that?
http://www.securityfocus.com/brief/959
Especially when auditors find this kind of vulnerability count?