WebGoat 3.5 was released today. It is a full J2EE web application that is
structured around "lessons" -- each one demonstrates a common web
application vulnerability. Download the latest version from
http://www.owasp.org/software/webgoat.html
This new version includes many improvements to existing lessons, better
lesson instructions, as well as some new lessons. We also upgraded the
standalone version to use Tomcat 5.5.4 and JDK 1.5.
We are actively working on some new lessons ( DOS, parameter injection, and
Buffer Overflow ) and I will create a new release as soon as those are
completed. If you have any ideas for new lessons... now would be the
appropriate time to send me an email.