Fetch: align CORS test with new "safelisted headers" rules

See https://github.com/whatwg/fetch/pull/736 for context.
diff --git a/cors/simple-requests.htm b/cors/simple-requests.htm
index 77ed8ee..be4b534 100644
--- a/cors/simple-requests.htm
+++ b/cors/simple-requests.htm
@@ -83,9 +83,9 @@
                         + uuid_token, true)
 
     client.setRequestHeader('Accept', 'jewelry')
-    client.setRequestHeader('accept-language', 'nn_NO,nn,en')
+    client.setRequestHeader('accept-language', 'nn-NO,nn,en')
     client.setRequestHeader('content-type', 'text/plain; parameter=extra')
-    client.setRequestHeader('content-Language', 'nn_NO')
+    client.setRequestHeader('content-Language', 'nn-NO')
 
     client.onload = simple_async.step_func(function() {
         assert_equals(client.getResponseHeader('content-type'), "text/plain", 'content-type response header')