Debian Security Advisory 1250-1 – It was discovered that cacti, a frontend to rrdtool, performs insufficient validation of data passed to the “cmd” script, which allows SQL injection and the execution of arbitrary shell commands.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53774/dsa-1250-1.txt
Source: https://packetstormsecurity.com/files/53774/Debian-Linux-Security-Advisory-1250-1.html

