$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PHP invoicing platform (BillForge v2.4.1) with admin settings allowing the public invoice template path to be changed, where the template is loaded via include() without sanitization. Solution: Changed template to nginx access log via path traversal, poisoned the log with a PHP webshell in the User-Agent header, then triggered RCE to read the flag from an environment variable.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar