A small Flask site that shows a few fixed pages. The page id from the URL path goes unsanitized into a SQLite query; the response only says whether a row was found.
Pas commencéDockercommit 5738c89x86_64 · aarch64Secret
Use a boolean-based blind SQL injection in the page id to extract data the application never displays, such as a user's password.
Le brief de ce lab se trouve dans son dépôt.