This is the code used to solve the NotBad.exe web challenge from Sogeti CTF qualifications 2019.
There is a second order SQL injection in username, while retreiving current user's notes.
The python script is a REPL shell you can script to test your payloads.