All of the above named sites use cookies within their mail services. A vulnerability in their web site allows remote attackers to cause it to reveal the cookie to third party sites by requesting an especially malformed URL (Containing a cross site scripting attack script).
...
More...