BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-1010
http://www.securityfocus.com/bid/5226
http://www.iss.net/security_center/static/9557.php
http://archives.neohapsis.com/archives/bugtraq/2002-07/0143.html