Tags: web xss
Rating:
XSS through the X-Forwarded-For header to steal the flag from admin. More details in the full writeup.
I don't remember