You probalby know these sources but just in case... OWASP Guide: http://www.owasp.org/documentation/guide Or if in a hurry there's the "Top Ten Web Application Vulnerabilities" http://www.owasp.org/documentation/topten Or Top 10 for PHP http://www.sklar.com/page/article/owasp-top-ten Patrick