If the request is made by a web page from a different server it would ordinarily be rejected because of the same origin policy.
Using CORS allows you to specify which servers you can accept requests from unless of course you are using ; Access-Control-Allow-Origin: *
More info ; https://developer.mozilla.org/en-US/docs/HTTP_access_control http://en.wikipedia.org/wiki/Cross-origin_resource_sharing