uWSGI 2.0.16 serving PHP, vulnerable to CVE-2018-7490: the php-docroot restriction misses URL-encoded ../ sequences, so a request reads files outside the document root.
Not startedDockercommit f5d72d3x86_64 · aarch64Secret
Exploit CVE-2018-7490 to read files outside the document root and read the flag.
The brief for this lab lives in its repository.