A comparison of 4 free and open source web application vulnerability scanners for inclusion in a continuous integration (CI) process for automated security testing.
How to detect SQLi vulnerabilities, examples of web application errors that indicate SQLi, and an introduction to web application vulnerability scanners.
You can find XSS vulnerabilities in a variety of ways; including manual testing, proxying web traffic, browser extensions, and web application vulnerability scanners.
XSS attacks were first seen almost immediately after JavaScript was released, but exploded after Samy brought down MySpace. Today, it is at the top of OWASP's list of web application security risks.