valentine - hxpCTF 2022 sk4d 2023-03-15 Web tl;dr SSTI in the valentine card bypass filter by setting ejs delimiter option RCE :yay: Read More hxpCTF
sqlite_web - hxpCTF 2022 ma1f0y 2023-03-14 Web tl;dr Create a sqlite3 extension with rce payload. Abuse werkzeug tempfile to upload the extension to server. load that extension using load_extension(‘/proc/self/fd/fd_no’); Read More hxpCTF