Web Application Security
A product search reflects query results. Use a UNION SELECT to pull data from the hidden secrets table and exfiltrate the flag.
loading simulatorβ¦
A 'check username availability' endpoint returns only Yes/No but is injectable. Extract the admin's secret token one character at a time, then submit it to get the flag.
loading simulatorβ¦