Calsir wrote:
Does the string contain the ASCII code of the letters?
yup
Please, tell me you did not _translate_ the address by hand...
Nope, I created a small javascript script 
I had noticed that attention url when connecting from firefox "smart" address bar, and played with it just to say "Hello World". I admit that I thought it was funny but harmless, therefore I failed to report it. You showed me otherwise. I feel slightly shamed.
Actually, a friend of mine had noticed a similar vulnerability on takeaplay quite a few years ago (and I never fixed it ).
Oh, and he exploited it in a much nastier way |