tent is not properly sanitized, active content, such as JavaScript can be injected.??? Sutton saw the second flaw, the ESPN ScoreCenter app sending users' passwords in clear text during the initial login, right as he set up an account to use the app. ???Anyone sniffing traffic on the network would be able to easily steal your username/password,??? he wrote. ???More often than not, when I see this f