the point is that spring's el was evaluating things
TWICE.
if i give my name as "$account.increment" then the worst you would expect to happen is that when my name is displayed it appears as "$account.increment". right?
in steps:
the jsp page contains <cout value="$user">
el looks at $user and finds the text "$account.increment" and *displays* that.
this is completely ok and does not require input sanitization. the code does not appear unsafe.
but no - there is the possibility that instead of simply displaying the value, spring will (may - i don't understand exactly when this is triggered) evaluate it. in steps:
the jsp page contains <cout value="$user">
el looks at $user and finds the text "$account.increment".
el *evaluates* $account.increment and increments the account. PLOP!
el displays the result of evaluating the account.
again: this occurs when the programmer was only intending to
display the value. because spring (by mistake) has a
second round of evaluation (first is $user to contents; second is contents to incrementing account), text that should simply be
displayed can be
evaluated.
see, for example https://docs.google.com/document/d/1dc1xxO8UMFaGLOwgkykYdghG...