Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by discovering (1) web credentials or (2) Wi-Fi credentials.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2502
http://archives.neohapsis.com/archives/bugtraq/2013-03/0080.html