$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PHP CMS with ?pg= parameter vulnerable to LFI via path traversal, no input sanitization on include(). Solution: Exploited LFI to include /proc/self/environ, injected PHP code via User-Agent header to achieve RCE and read /root/flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar