Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

UPDATED: Utah VPN Rule Enforcement Paused in Aylo Lawsuit

Provisions of a new Utah law making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification, which were set to come into force on Wednesday, have been put on hold until Sept. 3.

JustFor.fans Launches 'JFF Create' iPhone App

JustFor.fans (JFF) has launched its new iPhone creator management app, JFF Create.

ShootXEvents Joins ASACP as Media Sponsor

ShootXEvents has signed on as an in-kind media sponsor for the Association of Sites Advocating Child Protection (ASACP).

Pornhub Unblocks UK Users on iOS Devices, Citing Apple AV Effectiveness

Pornhub parent company Aylo on Tuesday announced that users in the United Kingdom will once again be able to access the popular site if they are using Apple devices and have confirmed their age through Apple’s U.K. age-verification process.

FSC Launches 'Know Your Rights' 1st Amendment Resource Page

The Free Speech Coalition (FSC) has launched "Know Your Rights," a resource page detailing First Amendment protest guidelines.

Utah VPN Rule for Adult Sites Takes Effect This Week

A new law in Utah comes into force Wednesday, making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification.

UPDATED: Court Approves Class Action in Labor Claims Against VMG

A U.S. district court has granted class certification in a civil lawsuit filed against Vixen Media Group (VMG) by retired performer Kenzie Anne, making it possible for additional performers to join in a class action against the company.

Brazil Invites Public Input on Guidelines for New Digital Law

Brazil’s National Data Protection Authority (ANPD) is soliciting public comments to help improve interpretation and application of the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

X3 Expo Unveils Euro All-Stars for Inaugural Amsterdam Edition

X3 Expo, Hollywood's premier adult entertainment expo, makes its European debut at Passenger Terminal Amsterdam Sept. 11-12, bringing together fans, creators, and industry insiders for the Continent’s largest assembly of adult entertainment stars, alongside a dazzling lineup of attractions spotlighting the cutting edge of modern media and pleasure tech.

2026 Pornhub Awards Nominees Announced

The list of nominees has been revealed for the eighth annual Pornhub Awards, presented by gaming platform 1win, which will be held May 27 in Los Angeles.

Show More