source: http://www.securityfocus.com/bid/61702/info BigTree CMS is prone to a cross-site request-forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible. BigTree CMS 4.0 RC2 is vulnerable; other versions may also be affected.