Treat your password like your toothbrush, don’t let anyone else use it and change it every six months. (Clifford Stoll)
Password security has been one of the longstanding IT security issue to date. While many IT administrators enforce periodic password change by the employees, many of them do not, turning a blind eye to on their vulnerability. It is advised that even home users choose three complex; easy to remember but difficult to guess passwords. Use the first password as a general one for the majority of sites that require passwords to login. The second password, use for your email account and only your email account. Finally use the third password for any websites that could have financial consequences such as online banking or payment sites.
Here's an article on SQL injection vulnerability : http://countermeasures.trendmicro.eu/orangefr-compromised-245000-clear-text-passwords-exposed/
