You could use something like Paros or Webscarab.
Basically it's a proxy that runs on localhost, intercepting all of your web traffic. It can automatically follow links, building a virtual map of the website. It also does some basic vulnerability testing, though I haven't had much luck with it. A lot of false positives, too. Worth a shot though. Definitely beats following links manually. I'd recommend Paros.
Assume that everything I say is or could be a lie.