The AIS3 Final sqlpwn PHP challenge contained a registration/login race condition that allowed a newly created account to authenticate before its corresponding lock record took effect. Its note-title handling also escaped input before truncating it to 32 bytes, enabling a one-byte truncation flaw that could alter the resulting SQL query and support SQL injection. The application used legacy mysql_* functions and unsalted MD5 password hashes, while an unauthenticated mode=info route exposed phpinfo() data.
After obtaining credentials for the orange administrator account, an attacker could use the administrative boom parameter to perform local file inclusion. Including a PHP session file with attacker-influenced content enabled PHP code execution, turning the chained authentication and injection flaws into full application compromise. The source also rendered note titles without evident output encoding and exposed the flag endpoint to any authenticated user, further weakening access controls.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A GitHub Gist containing the PHP source for the AIS3 Final CTF Web challenge sqlpwn.php was created. The code included registration, login, note, administrator, phpinfo, and flag-handling functionality.
Review of the sqlpwn source showed that mode=info invokes phpinfo() without an explicit authentication check, and that note titles are rendered without visible HTML output encoding. These behaviors can expose environment details and potentially enable stored script injection.
A technical analysis identified a registration/login race condition, a truncation-based SQL injection for obtaining the orange user's password hash, and administrator local file inclusion. The chain uses a controlled PHP session file to achieve PHP code execution after obtaining administrator status.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.