Company ignored reports of SQL injection

I recently discovered and reported a major SQL injection into a seemingly popular retail site and they've done nothing about it. I am unaware if they've ever read the email or not. What shall I do? The exploit leaks all usernames, passwords, emails, etc, and could thus be used maliciously by someone else if found.

submitted by /u/p0xq
[link] [comments]

from hacking: security in practice https://ift.tt/dvMaoNP

Comments