diff -ruBbdN cacti-0.8.6j/include/top_graph_header.php cacti-0.8.6j-patched/include/top_graph_header.php --- cacti-0.8.6j/include/top_graph_header.php 2007-01-17 19:23:10.000000000 -0500 +++ cacti-0.8.6j-patched/include/top_graph_header.php 2007-11-03 12:53:46.000000000 -0400 @@ -27,6 +27,10 @@ $using_guest_account = false; $show_console_tab = true; +/* ================= input validation ================= */ +input_validate_input_number(get_request_var_request("local_graph_id")); +/* ==================================================== */ + if (read_config_option("global_auth") == "on") { /* at this point this user is good to go... so get some setting about this user and put them into variables to save excess SQL in the future */