spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter. Upstream bug: https://github.com/Cacti/cacti/issues/877
Created cacti tracking bugs for this issue: Affects: epel-all [bug 1477093] Affects: fedora-all [bug 1477094]