- pom.xml引入
<dependency><groupId>org.codehaus.groovy</groupId><artifactId>groovy-all</artifactId><version>2.4.2</version></dependency>
- Java漏洞引入
package springbootsimple.demo;import groovy.lang.Binding;import groovy.lang.GroovyShell;public class Run003 {public static void main(String[] argv){GroovyShell groovyShell = new GroovyShell();Object value = groovyShell.evaluate("println 'hostname'.execute().text\n");// 执行groovyshell脚本System.out.println(value.equals(50));}}
