Following on from Andy’s email I just happen to come across these two articles. One details XSS attacks the other talks about Cross-Site Request Forgeries (CSRF) which i hadn’t really heard about before.

Read these everyone.
Cross-Site Request Forgeries and You
http://www.codinghorror.com/blog/archives/001171.html

Protecting Your Cookies: HttpOnly
http://www.codinghorror.com/blog/archives/001167.html

Andy’s docs are here:-

Tech\Application Security