It is still quite hard to believe how many web "designers" and "developers" implement sites that are vulnerable to SQL injection and Cross Site Scripting (XSS). Joel Spolsky blogged the other day about this problem in his " What's a SQL injection bug? " entry and Michael...