Java Security Code XMLInject SSRF URLRedirect IPForge XSS CRLFInjection RCE Usage 生成war包 mvn clean package 将target目录的war包,cp到Tomcat的webapps目录 重启Tomcat应用 http://localhost:8080/java-sec-code-1.0.0/rce/exec?cmd=whoami 返回 Viarus