During a recent penetration test I came across a Jenkins server. Having written a blog post on it, I was really excited and jumped straight to the /script url for the Groovy script console.
more here...........http://www.labofapenetrationtester.com/2014/08/script-execution-and-privilege-esc-jenkins.html
more here...........http://www.labofapenetrationtester.com/2014/08/script-execution-and-privilege-esc-jenkins.html