BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
http://www.iss.net/security_center/static/9557.php
http://archives.neohapsis.com/archives/bugtraq/2002-07/0143.html