It looks like you're new here. If you want to get involved, click one of these buttons!
I am developping some elearning slides on these subjects in great detail but im afraid you will have to wait until they are done, until then google it there pretty well documented
There are two very useful tools to explore, identify and then leverage web-applications.
Those are:
w3af - The web application attack and audit framework
http://w3af.sourceforge.net/
Web-Securify
http://www.websecurify.com/
They both focus on the application's and offer various methods of attack, be it reverse shells if possible or fuzzing!