webmedium

Campus One

scarlet

Task: E-commerce platform with admin panel access. Solution: API version downgrade to leak admin session, session hijacking, then SQL injection with comment bypass to extract flag from secrets table.

$ ls tags/ techniques/
filter_bypassapi_version_downgradesession_hijackingsqli_comment_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]