Hi,
There are a couple of podcasts at mightyseek.com which provide a hands-on introduction to SQL injection and XSS. The author has created a test site (
http://hackme.mightyseek.com/) to demonstrate these techniques. There some good information and links to useful sites there, take a look if you are new to either of these fields.
http://www.mightyseek.com/Regards,
Jim