We see simple online archiver:
\
Do you need to archive a file, but don’t have winrar at hand? Use our service - in a matter of seconds you can archive any file absolutely free.
When I upload file it really just creates archive with it. Let’s go into caido and check request:
the first thing I want to do is to try to inject code somewhere here:
Let’s check what is inside that archive
So we can`t run commands, but we have LFI.
Let’s try this:
Let’s run smth like cd ..;pwd
Nothing interesting here. Let’s go deeper with cd ..;cd ..;pwd
(slash doesn’t
work here)
and we got flag!