http://blogs.technet.com/srd/archive/2010/04/29/sharepoint-xss-issue.aspx
Here the workarounds
http://www.microsoft.com/technet/security/advisory/983438.mspx