TCMAN GIM SQL Injection Vulnerability in ArbolID Parameter

Vulnerability

A time-based blind SQL injection vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows attackers to retrieve, create, update, and delete databases by exploiting the ArbolID parameter in the frmPreventivosList.aspx page.

Impact

Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries to extract or modify database information. In this case, the vulnerability could be used to delete databases.

Remediation

Users can upgrade to the TCMAN GIM version released on November 12, 2024, to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.