graphimage.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graphstart or (2) graph_end parameter, different vectors than CVE-2007-3113.
{ "urgency": "low" }