Java template engines reach code execution through the platform's own classes rather than a scripting layer, so exploitation walks to java.lang.Runtime or ProcessBuilder and calls exec. Both engines here use ${ ... } for interpolation, so ${7*7} returning 49 is the shared probe (Velocity also responds to #set($x=7*7)$x).
The difference between them is the gadget: FreeMarker ships utility built-ins (Execute, ObjectConstructor, new) that construct and run objects directly, while Velocity has no such helper and is exploited by reflecting from an available class to Runtime.
Engines#
- FreeMarker: the
Execute,new, andapibuilt-ins, and thenew_builtin_class_resolvergate. - Velocity: reflection from
$class.inspect(...)toRuntime.getRuntime().exec.
References#
- Apache FreeMarker and Apache Velocity documentation
- PortSwigger Web Security Academy: Server-side template injection