http://www.owasp.org/index.php/Top_10_2007
another great resource is RSnake's blog:
http://ha.ckers.org