But wouldn't you need to add JAVA or PHP coding to get it to play a media file ? Well on the other hand it might lead to a security hole linking your server's error message html file to media unless you add it to your server's directory ...
I do remember that exploit that had to do with Apache and the default "It works!" message but wasn't this an exploit with a lot of the server's default test page ? ... :/
There's also a way of finding these exploits with servers using advanced Google operands and search terms if I remember correctly .... But there's always the risk of coming across a honey pot, which, I think, emulates a certain exploitable server or OS that traps the attacker by logging his attack ....