Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Pornhub, Stripchat: VLOP Designation Based on Flawed Data

In separate cases, attorneys for Pornhub and Stripchat this week told the EU’s General Court that the European Commission relied on unreliable data when it classified the sites as “very large online platforms” (VLOPs) under the EU’s Digital Services Act, news organization MLex reports.

New Age Verification Service 'AgeWallet' Launches

Tech company Brady Mills Agency has officially launched its subscription-based age verification solution, AgeWallet.

AEBN Publishes Popular Searches for September, October

AEBN has published the top search terms for the months of September and October from its straight and gay theaters in all 50 states and the District of Columbia.

Creator, Influencer YesKingzTV Passes Away at 47

Adult content creator and social media personality YesKingzTV, aka Micheal Willis Heard, has passed away at the age of 47.

Pre-Nominations Now Open for 2026 TEAs

The pre-nomination period for the 2026 Trans Erotica Awards (TEAs) is now open.

FSC Releases Updated Age Verification Toolkit

The Free Speech Coalition (FSC) has announced the release of its updated age verification toolkit.

Duke Tax Joins Pineapple Support as Supporter-Level Sponsor

Duke Tax has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

UK Moving Ahead with Plan to Outlaw 'Choking' Content

The U.K. government has announced its intent to follow through on criminalizing “choking” content, a plan that was announced earlier this year.

Italy to Require Age Verification for Adult Sites

Italian media regulator AGCOM has announced that all sites and platforms hosting adult content will be required to implement age verification systems to prevent access by users under 18.

'MILFlicious' Launches Through YourPaysitePartner

MILFlicious.com has officially launched through YourPaysitePartner (YPP).

Show More