Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Sansyl Group Acquires Blue Donkey Media

Sansyl Group, parent company of AdultPrime Network, has acquired Blue Donkey Media B.V., owner of Dutch adult site Meiden van Holland, among several other erotic websites and television channels.

Pineapple Support to Hold Mental Health Summit

The annual Pineapple Support Mental Health Summit is taking place Dec. 15-17.

Ofcom Fines AVS Group $1.3 Million for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed a penalty of one million pounds, or approximately $1.3 million, on AVS Group Ltd. after an investigation concluded that the company had failed to implement robust age checks on 18 adult websites.

Updated: Aylo to Help Test EU Age Verification App

Pornhub parent company Aylo plans to participate in the European Commission’s pilot program for its “white label” age verification app, a spokesperson for the company has confirmed.

Missouri Lawmaker Attempts to Revive 'Health Warnings' for Adult Sites

A Missouri state representative has introduced a bill that would require adult sites to post notices warning users of alleged physical, mental, and social harms associated with pornography, despite a previous federal court ruling against such requirements.

New Age Verification Service 'BorderAge' Launches

French startup company Needemand has officially launched its subscription-based age verification solution, BorderAge.

Ruling: Italy's 'Porn Tax' Applies to All Content Creators

Italy’s tax revenue agency has ruled that the nation’s 25% “ethical tax” on income generated from adult content applies even to smaller independent online content creators.

Proposed New Hampshire AV Bill Appears to Violate Constitution

A bill in the New Hampshire state legislature, aimed at requiring adult sites to age-verify users in that state, contains a provision that seemingly contradicts the Supremacy Clause in Article VI of the U.S. Constitution.

AEBN Publishes Report on Fetish Trends

AEBN has published a report on fetish categories from its straight and gay theaters.

Online Child Protection Hearing to Include Federal AV Bill

A House subcommittee will hold a hearing next week on a slate of bills aimed at protecting minors online, including the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law.

Show More