Try exploiting the ssti to run arbitrary code and get the flag.
Box: luhack-web-0
luhack-web-0
Port: 8084
Url: http://100.110.89.151:8084