As reported on slashdot:
"The San Francisco Chronicle reports that Google has released Jarlsberg, a 'small, cheesy' web application specifically designed to be full of bugs and security flaws
as a security tutorial for coders, and encourages programmers to try
their hands at exploiting weaknesses in Jarlsberg as a way of teaching
them how to avoid similar vulnerabilities in their own code. Jarlsberg
has multiple security bugs ranging from cross-site scripting and
cross-site request forgery, to information disclosure, denial of
service, and remote code execution. The codelab is organized by types of vulnerabilities."