Chaining a libinjection-evading second-order SQLi into a PostGIS BAG TEMPLATE gopher SSRF, rewriting Patroni config in unauthenticated etcd to get archive_command RCE
A trilogy of Web Security challenges focusing on WAF bypasses, SQL Injection chains, and SSTI to achieve RCE without using quotes or periods.