"Attempted XSS in GET" is not an nBill error message. Most likely it is being triggered by a mod_security rule which is detecting a 'false positive' - ie. mistakenly thinking that a legitimate nBill feature is an attack. If the error did not affect performance you can either just ignore it, or ask your hosting company to tweak the mod_security rules so that it doesn't trigger the error.