Assume a web app (served over http) has a tag with a src that is another domain. The external script is doing things with cookies and/or localStorage. What domains cookies can it access?
<!-- on example.org -->
<script src='http://anotherexample.org/script.js'> <!-- This script messes with cookies -->
My intuition tells me the the cookies that it manipulates are those that belong to example.org. But how does this work?