CSC-382 student here. I was trying to solve the "Logo" challenge on the CTF and entered π (UTF-8 03c0) into the "Suggested Retail Price" box. It didn't occur to me until I saw the resulting error message that the system would try to parse it as a number, and would not read it correctly. After doing this, any attempt to upload an image resulted in the following message (or something similar):
Warning: copy(/var/www/hiwa/uploads/somethin.png): Failed to open stream: No such file or directory in /var/www/hiwa/hiwa/products.php on line 59
I have not yet confirmed that entering π was the cause of this issue, but I think it likely. Entering π again (updating an existing product this time) results in this error:
Warning: pg_query(): Query failed: ERROR: column "π" does not exist LINE 1: ...roductdescr='XL T-shirt with SQLi print', msrp=π, imag... ^ in /var/www/hiwa/hiwa/products.php on line 65