Rating:

### TL;DR
Craft a malicious cookie via Padding Oracle to bypass a whitelist and do Command Injection to extract `flag.txt`.

Original writeup (https://blog.pspaul.de/posts/pwn-ctf-2018-converter/).