Skip to main content

Now SQL injection flaw found on Tesco website

posted onAugust 21, 2012
by l33tdawg

Yet another vulnerability on the Tesco website has been confirmed by a researcher, who lambasted the supermarket giant for its “unprecedented” silence on fixing various security issues.

Following claims that Tesco is not hashing, salting or encrypting customer passwords, and has an XSS  flaw on its main website, customers and onlookers have bemoaned the company’s lack of action.

There has been no confirmation that fixes have been implemented and the issues had not been addressed at the time of publication, whilst data protection watchdog the Information Commissioner’s Office (ICO) is looking into the matter. But now another vulnerability on the Tesco website has been uncovered and verified, said security expert Troy Hunt, which could place the firm and its customers at risk. The flaw was highlighted in the comments section of one of Hunt’s blog posts.

Source

Tags

Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th