BigAce versions 2.7.1 and below suffer from cross site request forgery and cross site scripting vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/89904/Bkis-01-2010.txt
Source: https://packetstormsecurity.com/files/89904/BigAce-Cross-Site-Scripting-Cross-Site-Request-Forgery.html

