Under Construction: exploit the SQL injection, extract the needed data, and reach the flag.