A variable is passed to header(), allowing response splitting or header injection.
Validate header values and strip CR/LF characters before calling header().