TCMAN GIM
cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*
- 11
A time-based blind SQL injection vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows attackers to retrieve, create, update, and delete databases by exploiting the ArbolID parameter in the frmPreventivosList.aspx page.
Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries to extract or modify database information. In this case, the vulnerability could be used to delete databases.
Users can upgrade to the TCMAN GIM version released on November 12, 2024, to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.