By escaping URL characters it's possible to bypass URL filtering.
vulners.com/securityvulns/securityvulns:doc:5996