Rating:
Bypass authentication by using an UNION-based SQL injection, then exploit a path traversal to read the flag.
I don't remember