Source code examples for the Lightning Talk: Fun With Templates
These are some simple examples of using Apache Velocity Templates, including an example of using template injection for remote code execution.
These examples are for an internal lightning talk given at LMAX demonstrating the research presented by James Kettle of PortSwigger Security at BlackHat USA 2015.
For more details on his research, see http://blog.portswigger.net/2015/08/server-side-template-injection.html