Piyush Malik, an independent security researcher from India, has identified an Expression Language (EL) Injection vulnerability in Zong, a mobile payments provider acquired by PayPal in July 2011 for $240 million (171 million).
EL Injection vulnerabilities were first documented in 2011 by Stefano Di Paola of Minded Security and Arshan Dabirsiaghi of Aspect Security. These are attacks that target the EL interpreter.
EL vulnerabilities can be exploited for …