Mitre, via its Common Weakness Enumeration effort, in conjunction with SANS, just published the 2010 CWE/SANS Top 25 Most Dangerous Programming Errors. Heading the list are:
- Cross-site Scripting (Score = 346)
- SQL Injection (330)
- Classic Buffer Overflow (273)
- Cross-Site Request Forgery (261)
- Improper Access Control (219)
For each weakness this report provides a Description, Prevention and Mitigation techniques, and links to more reference material. This is well worth reading.

I was very excited to read this until I realized it was in PSD format. Yuck!
Posted by: Carl | Sunday, 21 February 2010 at 05:41 PM
Carl,
First, the format of the document is PDF. Second, I dont feel I have the right to convert it. Third, I will email it to you privately. If you have a Gmail account, they will convert it for you automatically.
Bill
Posted by: riskpundit | Sunday, 21 February 2010 at 08:24 PM