Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/22788http://www.securityfocus.com/bid/15127http://securitytracker.com/id?1015078http://marc.info/?l=bugtraq&m=112967149509401&w=2http://secunia.com/advisories/17253/http://www.osvdb.org/20073