Kueski interview question

What typical web-application security vulnerabilities do you know? Describe best practices to avoid them.