Multiple SQL injection vulnerabilities in graphxport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graphstart, (2) graphend, (3) graphheight, (4) graphwidth, (5) graphnolegend, (6) printsource, (7) localgraphid, or (8) rraid parameter.