# (CVE-2020-26217)XStream XML反序列化远程代码执行
https://x-stream.github.io/CVE-2020-26217.html
“`xml
“`
“`
XStream xstream = new XStream();
xstream.fromXML(xml);
“`
![image-20201117135642244](/static/qingy/(CVE-2020-26217)XStream_XML反序列化远程代码执行/img/image-20201117135642244.png)
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
请登录后查看评论内容