Updated cacti package fixes security vulnerability:
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parentid parameter in an itemedit action (CVE-2016-3172).
SQL injection vulnerability in graphview.php in Cacti 0.8.8.g and earlier allows remote authenticated users to execute arbitrary SQL commands via the hostgroup_data parameter (CVE-2016-3659).