CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "spam proxy" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24540
http://www.vupen.com/english/advisories/2006/0459
http://vc.thauvin.net/cvs/cgi/mailback/mailback.pl?view=log