Hi,
just a real quick hotfix to the critical vulnerability described in this advisory:
<Files cmd.php>
Deny from All
</Files>
Put this into the .htaccess in your cacti directory and you should be good. This does not have any impact on the poller cronjob and does not require code or ini changes.