SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
https://www.exploit-db.com/exploits/4848
https://exchange.xforce.ibmcloud.com/vulnerabilities/39454
http://www.securityfocus.com/bid/27170
http://www.aspapp.com/content.asp?CatId=197&ContentType=Downloads