Now SQL injection flaw found on Tesco website

http://en.wikipedia.org/wiki/Tesco

Yet another vulnerability on the Tesco website has been confirmed by a researcher, who lambasted the supermarket giant for its “unprecedented” silence on fixing various security issues.

Following claims that Tesco is not hashing, salting or encrypting customer passwords, and has an XSS  flaw on its main website, customers and onlookers have bemoaned the company’s lack of action.

Tags: 

Read more: Now SQL injection flaw found on Tesco website

Story added 21. August 2012, content source with full text you can find at link above.