Month Of PHP Security – An SQL Injection vulnerability was discovered in Cacti that allows to retrieve all data from the database. In Cacti installations with publicly viewable graphs this vulnerability is a pre-auth SQL injection vulnerability. Cacti versions 0.8.7e and below are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/89878/MOPS-2010-023.pdf
Source: https://packetstormsecurity.com/files/89878/MOPS-2010-023-Cacti-Graph-Viewer-SQL-Injection.html