lol
that's too evil.......
inject http header for your own request is easy, there are tons of tools to
do that.
the tricky thing is how to inject someone else's http header.
I believe you could still find those info on internet.
But somehow it will be a 0-day security fix for those clients who have the
bug so in general the exploit life wont be long.