The root cause of these type of bugs is allowing one webpage to call a script residing on another domain, great for inserting adverts, not so great for security.

