Rating:

tl;dr

* SSRF using file_get_contents() and CRLF in ini_set()
* basic Header quirks to bypass waf
* sqli using column trick in SQLite to get the flag

Original writeup (https://blog.bi0s.in/2023/01/24/Web/Vuln-Drive2-bi0sCTF222023/).