An SQL injection was found in /cacti/graphs_new.php, affected versions 0.8.8f and older. Vulnerable code with reproducer can be found here: http://seclists.org/fulldisclosure/2015/Dec/att-57/cacti_sqli%281%29.txt
Created cacti tracking bugs for this issue: Affects: epel-all [bug 1291223]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.