Launchpad.net

CVE 2013-1434

Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

See the CVE page on Mitre.org for more details.