This wiki section contains links to papers which describe the most common PHP security issues.
http://securephp.damonkohler.com/index.php/Email_Injection