Isn't this XSSI, not CSRF?
I agree, this is not the attack I think of when somebody mentions CSRF. Well, the solution at least isn't. I would be very suspicious of anyone who claimed to solve their CSRF holes by not using arrays.
Here are a couple of resources that go a litle more into XSSI:
Google tech talk: http://www.youtube.com/watch?v=jC6Q1uCnbMo&feature=playe...
Gruyere codelab: http://google-gruyere.appspot.com/part3#3__cross_site_script...