Via TechNet Microsoft recently has published an alert about a possible (i.e., not yet verified) vulnerabiltity in SharePoint versions WSS 3 and MOSS 2007. As stated in the message:
The vulnerability could allow an attacker to run arbitrary script that could result in elevation of privilege within the SharePoint site, as opposed to elevation of privilege within the workstation or server environment.
Until this threat is verified and a fix is published, the suggested action to avoid any harm is to temporarily restrict access to SharePoint Help.aspx. Details on how to do this are stated in the alert.
