$ cat writeup.md…
$ cat writeup.md…
compfest2026
Task: a Flask ticketing site exposed a broken promo endpoint and a MariaDB-backed match view vulnerable to SQL injection. Solution: use UNION SQLi to learn the 12-column layout, write the missing Jinja template with INTO OUTFILE, then trigger final-week to read the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar