Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

DarkFans Rolls Out 'Configure Limits' Solution

DarkFans has debuted its Configure Limits monetization solution for creators.

Clips4Sale, Free Speech Coalition Partner for 'Creator Workflow' Webinar

Clips4Sale (C4S) and Free Speech Coalition (FSC) have partnered for a webinar titled “Organization & Workflow: Simple Systems for Busy Creators.”

Pineapple Support, Streamate Partner for 'Self-Parenting' Support Group

Pineapple Support and Streamate are hosting a free online support group focused on self-care for performers, titled "Self-Parenting: Becoming Your Own Safe Space."

Nerds of Porn to Relaunch Site Through MyMember.site

Nerds of Porn is relaunching its membership site through MyMember.site on Aug. 14.

SCREEN Act Back in Play: Federal AV Bill Faces Senate Hearing

The U.S. Senate Committee on Commerce, Science, and Transportation has slated a markup session this week for the SCREEN Act, which would mandate site-based age verification of users accessing adult content online on a national level.

Clips.com Launches Lifetime Creator Referral Program

Recently launched creator platform Clips.com has introduced its new lifetime creator referral program.

BranditScan Rolls Out 'Leak Detection' Update

BranditScan has updated its Leak Detection feature for OnlyFans creators.

Arcom Targets 31 Adult Sites Over Age Verification

French media regulator Arcom on Wednesday announced that it is taking action against 31 adult websites that the agency says have failed to implement age verification as required under France’s Security and Regulation of the Digital Space (SREN) law.

AEBN Publishes Popular Searches for May, June

AEBN has published the top search terms for May and June from its straight and gay theaters in all 50 states and the District of Columbia.

Show More