Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Anti-Censorship Bill Could Shield US Sites From Foreign AV Laws

A Republican congressman has introduced legislation to bar U.S. courts from helping to enforce any foreign law restricting speech that would domestically be protected under the First Amendment, potentially including foreign age verification laws.

X3 Expo 2027 All-Stars Unveiled, Dates Set for Jan. 8-9

X3 Expo will make its L.A. LIVE debut at the JW Marriott on Jan. 8-9, bringing together fans and industry insiders for North America’s largest assembly of stars, alongside a dazzling lineup of attractions spotlighting the cutting edge of modern media and pleasure tech.

BranditScan Rolls Out Real-Time Telegram Leak Scans, Takedowns

BranditScan has launched Telegram Bot, a new feature that lets creators scan Telegram in real time for leaked content.

Pineapple Support to Host 'Suicide Survivors' Support Group

Pineapple Support is hosting a free online support group for performers affected by suicide.

Studio Vanniall Signs Exclusive Partnership Deal With PAYSITE

Studio Vanniall has signed an exclusive partnership deal with PAYSITE.

AEBN Publishes Popular Searches by Country for June, July

AEBN has released the list of popular searches from its straight and gay theaters, by country, for June and July.

Appeals Court Upholds Section 230 Immunity in XVideos Case

The U.S. Court of Appeals for the 9th Circuit has upheld a lower court’s ruling that Section 230 protects WebGroup Czech Republic from liability in a case involving user-uploaded CSAM on its tube sites.

Aylo Moves to Settle Two 'Children of Pornhub' Class-Action Lawsuits

Aylo has agreed to terms for a settlement with the plaintiffs in two long-running class actions over allegations that former Pornhub parent company MindGeek knowingly allowed and profited from CSAM on its sites.

Tigerlilly Launches 'SugarCoatedSweethearts' Through PAYSITE

Tigerlilly has launched SugarCoatedSweethearts.com through PAYSITE.

ASACP Marks 30-Year Anniversary

ASACP is celebrating 30 years of operation, during which it has received over 1.3 million reports from web admins and the public about suspected child pornography.

Show More