Appscan injected the following into a test request GET /bank/customize.aspx?lang=Foobar%3f%0d%0aAppScanHeader:%20AppScanValue%2f1%2e2%2d3%0d%0aSecondAppScanHeader: %20whatever HTTP/1.0. What kind of vulnerability is appscan testing for?
Cross site request forgery
Cross site scripting
HTTP Response Splitting
SQL injection