XSS or XSRF that requires header injection