TCMAN GIM
cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*
- 11
A time-based blind SQL injection vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows an attacker to retrieve, create, update, and delete databases by exploiting the ArbolID parameter in the /GIMWeb/PC/frmCorrectivosList.aspx endpoint.
Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information.
The vulnerability has been fixed in the TCMAN GIM version 20241112 release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.