try a search for trusted variables.
xcart will strip code out of certain things as a security measure
you could also hard code something like this into your page
Code:
{if $extra_field[0].field_value}
<a href="http://yourstore.com/filesdir/{$product.productid}.pdf
">Download PDF</a>
{/if}
this will check if the first extra field has anything in it (such as Y) and if it does it will show the download link for the pdf which you must name as the product id number with the pdf extension
ie
productid = 456
would turn into
Code:
<a href="http://yourstore.com/filesdir/456.pdf
">Download PDF</a>