Rating:

XSS using DOM clobbering and browser's antiXSS. Redis injection and PHP disabled_functions' bypass.

Original writeup (https://blog.ka0labs.net/post/33/).