Imperva (http://www.imperva.com ) isolated the four most prevalent Web application attacks:

1. Directory traversal = 37%
2. cross site scripting =36%
3. SQL injection =23%
4. Remote file include =4%

Sources:-
http://www.imperva.com/index.html
http://www.pcmag.com/article2/0,2817,2389117,00.asp