RULE(RULE ID:306968)

Rule General Information
Release Date: 2015-03-19
Rule Name: Instantcms 'orderby' Parameter SQL Injection Vulnerability (CVE-2013-6839)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the orderby parameter to catalog/[id].
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:63842
Solutions
The vendor has updated advisory on its official website. Please check it for more information.