Filename can be spoofed by using large number of spaces, display icon - with Content-Type header.
vulners.com/securityvulns/securityvulns:doc:11072