Giddy
An ASP.NET product-search page is SQL-injectable, and MSSQL's xp_dirtree is abused to coerce the SQL service account into authenticating to an attacker SMB share — capturing and cracking a NetNTLM hash for user stacy, whose credentials log straight into WinRM as a local administrator for the user flag.