Cody's First Blog
Test path accessiblity
Create comment with body
Submit to get a flag
By viewing page source found a path to admin login page
Try another value of page
An error message was received
So the value of page is a filename without suffix
Keep on trying, seems subpath php.ini is accessible
Try another possible file name
It leads to a flag at the bottom of the response page
Comment with content
Approve this comment in ‘Pending Comments’ page.
Visit home page via
Found the 3rd flag in source code of index.php