old-30 -- MySQL Connection Hijack

<?php
if ($_GET["view_source"]) {
highlight_file(__FILE__);
}
($db = mysqli_connect()) or die();
mysqli_select_db($db, "chall30") or die();
($result = mysqli_fetch_array(mysqli_query($db, "select flag from chall30_answer"))) or die();
if ($result[0]) {
include "/flag";
}
?>

Last updated