$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: Web application using Sedna XML database with XQuery. Solution: XQuery injection in login field to extract flag document, bypassing authentication by injecting known hash.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar