Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Pineapple Support Relaunches Site

Pineapple Support has updated and relaunched its website.

Arcom-Targeted Sites Implement Age Verification in France

Five high-traffic adult websites based outside of France have implemented age verification as required under the nation’s Security and Regulation of the Digital Space (SREN) law, after receiving warnings from French media regulator Arcom.

Goddess Lilith Launches 'Adultpreneurs' Networking Site

Goddess Lilith has launched Adultpreneurs, a new community and networking site.

Adult Shoot Location Marketplace 'FckSpace' Launches

FckSpace, a new platform aimed at simplifying location sourcing for adult productions, is now live

Florida Attorney General Dismisses AV Suit Against Segpay

The Florida attorney general’s office on Monday agreed to dismiss claims against payment processor Segpay in a lawsuit over alleged noncompliance with the state’s age verification law.

FTC Weighs Reboot of 'Click to Cancel' Rulemaking Process

The Federal Trade Commission has invited public comments on a petition to renew trade regulation rulemaking concerning negative option plans, after a federal court previously vacated a “click-to-cancel” rule aimed at making it easier for consumers to cancel online subscriptions.

VRPorn.com Releases 2025 'Annual Report'

VRPorn.com has released its Annual Report, highlighting its audience favorites from throughout 2025.

MrPornGeek Launches 'Visibility Boost' System

MrPornGeek has introduced a new paid visibility boost feature designed to temporarily increase advertiser exposure across select sections of its platform.

New Federal Bills Aim to Repeal Section 230

Members of Congress this week introduced two bills calling for the repeal of Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

RM11 Joins Pineapple Support as Supporter-Level Sponsor

RM11 has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Show More