WebApp Sec mailing list archives
Many webmail apps use a DB backend, so SQL injection may qualify, too.
By Date By Thread