CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.
http://www.securitytracker.com/id/1036736
http://www.securityfocus.com/bid/92794
http://www.securityfocus.com/archive/1/539366/100/0/threaded