Multiple SQL Injection/XSS bugs
Risk: Medium-High
The company which can't secure it's site is providing services on Security. WOW !!!
http://www.tcs.com/esecurity => Check this out ;)
SQL Injection - Do you want me to be the DBA ;) ??

Cross Site Scripting - Do you see phishing coming your way ;) ??

I sent an email back in December 2006, they're so responsible not to fix their bugs even after 2 months. I sent the email to their Information Security Manager, Chennai, not to admin/webmaster/or any default address. No response until date (see picture)
Email sent to "Full-Disclosure - We believe in it ;)"
Cheers :)