$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PHP CMS with theme import feature that extracts ZIP archives to a web-accessible directory without filtering file types inside the archive. Solution: include a PHP webshell (shell.php) inside a valid theme ZIP alongside theme.json, upload via /themes/import, then access the extracted webshell at /uploads/themes/<name>/shell.php for RCE.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar