owasp has released a project called webgoat. It is a web application designed for teaching users about web application vulnerabilities such as xss, sql injection, etc. It can be found at - http://www.owasp.org/webgoat/

Sounds very cool to me.