Consider the following piece of JSP:
The value of ${flashVars} conta
${flashVars}
Use fn:escapeXml().
<%@ taglib prefix="fn" uri="http://java.sun.com/jsp/jstl/functions" %> ... <param name="FlashVars" value="${fn:escapeXml(flashVars)}" />