saw a link on /. that we should all take a look at. I've already downloaded the pdf of the report. Interesting reading.
http://developers.slashdot.org/developers/03/01/13/1319201.shtml?tid=172
Top Vulnerabilities in Web Applications
http://www.owasp.org/