Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24642
http://www.vupen.com/english/advisories/2006/0570
http://www.securityfocus.com/archive/1/450047/100/100/threaded
http://www.securityfocus.com/archive/1/440586/100/100/threaded