Cross Site Scripting

Do e-commerce business with, and have webmail hosted by, secure companies only. Can someone hijack your login session through a vulnerability of their website? Obviously, this is not a client issue, but a problem within the servers.

My non-exhaustive list of examples of vulnerabilities (some may have been fixed since, but others are surely waiting to be discovered):

Cross Site Scripting is often abbreviated as XSS or CSS, though the latter also means Cascading Style Sheets...

For further information on XSS see:

Paul Szabo 10 Oct 10