Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Seoul Authorities Force Cancellation of Adult Expo for 'Distorting Perceptions of Sex'

After Seoul authorities repeatedly prevented 2024 KXF The Fashion from finding a suitable venue, event organizers have canceled the popular Korean adult industry expo, which was scheduled for this week.

FSC to Hold Discussion on Adult Industry Rights With Congressional Candidate Joe Cohn

Free Speech Coalition will hold a virtual discussion with Joe Cohn, a strong advocate for the adult industry’s rights who is running for Congress in November.

Sophie Dee, Ricky Johnson to Deliver 'XBIZ Talks' at Miami Conference

XBIZ is pleased to announce that Sophie Dee and Ricky Johnson will each deliver an “XBIZ Talk” at next month’s XBIZ Miami conference

FSC to Host Webinar on Derisking and the Adult Industry

The Free Speech Coalition (FSC) is hosting a webinar on derisking, titled "Derisking: Examining Its Impact on the Adult Industry's Access to Banking," on April 24 at 11 a.m. (PDT).

Democratic Governor Fails to Veto Kansas Age Verification Bill

Kansas’ Democratic governor, Laura Kelly, expressed strong reservations about the state’s version of the age verification bills being sponsored around the country by anti-porn religious conservative activists, but ultimately decided not to veto it, allowing the legislation to become law by default without her signature.

FSC's Alison Boden Testifies Against California Age Verification Bill, Urges Action to Defeat It

Free Speech Coalition Executive Director Alison Boden testified Tuesday against AB 3080, California’s version of the age verification bills being sponsored around the country by anti-porn religious conservative activists.

Phoenix Marie Sues Aylo, Danny D Over Incident on Digital Playground Set

Phoenix Marie has filed a lawsuit against Aylo, performer/producer Danny D and other defendants, alleging she has suffered defamation and damage to her career over a 2023 incident on a Digital Playground set in Spain.

New Premium Creator Platform 'Lemon Social' Launches

Premium creator platform Lemon Social has debuted.

MomPOV Producer Pleads Guilty in GirlsDoPorn Case

MomPOV producer Doug Wiederhold, who was formerly the partner of GirlsDoPorn owner Michael Pratt as well as the first male talent for GDP, pleaded guilty Thursday to a federal conspiracy charge.

Streamate Exec Liz Rek Joins FSC Board

The Free Speech Coalition board of directors has tapped Streamate executive Liz Rek as its newest member, effective immediately.

Show More