Description
Umbraco CMS includes a ClientDependency package that is vulnerable to a local file inclusion (LFI) in the default installation. The ClientDependency package, used by Umbraco, exposes the "DependencyHandler.axd" file in the root of the website. This file is used to combine and minify CSS and JavaScript files, which are supplied in a base64 encoded string.
Remediation
The Umbraco team have released a fixed version of the ClientDependency package. For more information consult the Umbraco security advisory listed in web references.
References
Related Vulnerabilities
WordPress Plugin Light Post 'abspath' Parameter Remote File Include (1.4)
WordPress Plugin Grow by Tradedoubler-Advertiser for WooCommerce Local File Inclusion (2.0.21)
WordPress Plugin SAM Pro (Free Edition) Local File Inclusion (1.9.6.67)
WordPress Plugin Spicy Blogroll Local File Include (1.0.0)
WordPress Plugin Extensive VC Addons for WPBakery page builder Local File Inclusion (1.9)