Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
CVSS Metrics