BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).
http://www.securityfocus.com/bid/6044
http://www.iss.net/security_center/static/10466.php
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0041.html