BadBlue invalid null byte vulnerability

Summary
It was possible to read the content of /EXT.INI (BadBlue configuration file) by sending an invalid GET request. A cracker may exploit this vulnerability to steal the passwords.
Solution
upgrade your software or protect it with a filtering reverse proxy