I'm trying to have a better knowledge about this topic.
So far I've found these:
- Towards Automated Malicious Code Detection and Removal on the Web [PDF]
- Ruby On Rails Security Guide (It's RoR specific but it covers a lot of topics, including XSS)
- Cross-Site Scripting (XSS examples)
Do you know some useful link?