SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.
https://www.exploit-db.com/exploits/1931
https://exchange.xforce.ibmcloud.com/vulnerabilities/27283