Mandriva Linux Security Advisory 2010-117 – SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which bypasses the validation routine. The updated packages have been patched to correct this issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/90729/MDVSA-2010-117.txt
Source: https://packetstormsecurity.com/files/90729/Mandriva-Linux-Security-Advisory-2010-117.html

