Security musings (reflectorium)
Security musings (reflectorium)
WASS statistics
WASS Weba Application Security Statistics 2007 gives some really nice insights, e.g. % of type of vulnerabilty on average site *and* how likely they are detected by automated scans vs. penetration testing. Automated scans are good at finding low and medium ones. Penetration test are good at finding high findings.
http://packetstormsecurity.org/papers/general/wasc_wass_2007.pdf