There is a good book called application security, or web app security, which has a picture of a cowboy hat on the front...can`t remember what the bloody name is at the moment.

I think if you already have a couple of books then you can stick with those and just read the papers from SPI, NGS etc...

Also, have a look at WebGoat http://www.owasp.org/software/webgoat.html as you can learn alot form there.