Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6742
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0695