"A handy cheatsheet which points out web application vulnerabilities that should be checked during a penetration test assignment."
http://www.secguru.com/web_application_cheatsheet_version_2