I was trying to hit a web service on a different domain using jQuery's ajax method. After doing some research it looks like it does not allow this is by design to prevent cross site scripting.
I came across a work around which was to include this line:
$.support.cors = true;
at the top of my javascript code. From what I understand this enables cross site scripting in jQuery.
Does having this line of code make my site more vulnerable to attack? I've always heard XSS discussed as a security issue, are there legitimate uses for XSS?