PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.9%