Back
CVE-2005-1821
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.
Published: Jun 1, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| powerscripts.org | powerdownload | 3.0.2 |
| powerscripts.org | powerdownload | 3.0.3 |
GitHub Security Advisory GHSA-7v35-w4g5-fc2j
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3...
References (10)
- http://marc.info/?l=bugtraq&m=111755754126095&w=2
- http://secunia.com/advisories/15537 Vendor Advisory
- http://securitytracker.com/id?1014078 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/13822 Exploit, Vendor Advisory
- http://www.soulblack.com.ar/repo/papers/advisory/powerdownload_advisory.txt Exploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=111755754126095&w=2
- http://secunia.com/advisories/15537 Vendor Advisory
- http://securitytracker.com/id?1014078 Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/13822 Exploit, Vendor Advisory
- http://www.soulblack.com.ar/repo/papers/advisory/powerdownload_advisory.txt Exploit, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.89%
Top 14% most likely to be exploited
Threat Score
30.9 / 100
Data Sources
NVD
EPSS
GitHub