cbcvebase.
CVE-2007-3112
published 2007-06-07

CVE-2007-3112: graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large…

PriorityP424high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.41%
82.3th percentile
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.

Affected

6 ranges
VendorProductVersion rangeFixed in
cacticacti>= 0 < 0.8.6j-1.10.8.6j-1.1
cacticacti>= 0 < 0.8.6j-1.10.8.6j-1.1
cacticacti>= 0 < 0.8.6j-1.10.8.6j-1.1
cacticacti>= 0 < 0.8.6j-1.10.8.6j-1.1
debiancacti< cacti 0.8.6j-1.1 (bookworm)cacti 0.8.6j-1.1 (bookworm)
the_cacti_groupcacti<= 0.8.6i

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.