Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Releases Statement on Wisconsin Governor Vetoing AV Bill

The Free Speech Coalition has released a statement on Wisconsin Governor Tony Evers' veto of the state's age verification legislation.

AV Bulletin: West Virginia Enacts AV Law, Wisconsin Bill Vetoed

This roundup provides an update on the latest news and developments on the age verification front as it impacts the adult industry.

Woodhull Survey Reveals Concern Among Sex Educators Over AV Laws' Impact on Access

A national survey of sex educators by the Woodhull Freedom Foundation found that a majority of sex educators and sexual health professionals are concerned that age verification (AV) laws will negatively impact access to information and resources.

Clips4Sale Wins Trademark Infringement Case Against Fraudulent Domain

The World Intellectual Property Organization (WIPO) has ruled in favor of content platform Clips4Sale in a case against a website using a similar domain to impersonate the site.

Pineapple Support, SextPanther to Host Stress Management Support Group

Pineapple Support and SextPanther are hosting a free online support group focused on stress management for performers.

Goddess Tangent Launches New Site Through Grooby's Blue.xxx

Goddess Tangent has launched her new membership site, TangentOD.com, through Grooby's website management company Blue.xxx.

Keiran Lee Guests on Chaturbate's 'Sex Tales' Podcast

Keiran Lee is the latest guest on Chaturbate’s “Sex Tales” podcast, hosted by Melissa Stratton and Vanniall, and streaming on the company’s “Camming Life” YouTube channel.

FSC Talks Age Verification on Capitol Hill

The Free Speech Coalition (FSC) has published a blog post detailing the organization's talks on age verification on Capitol Hill in Washington.

FTC Warns PayPal, Stripe, Visa, Mastercard Against Debanking

Federal Trade Commission Chairman Andrew Ferguson sent letters on Thursday to the CEOs of PayPal, Stripe, Visa and Mastercard, warning them against debanking practices — including denying customers access to services based on lawful business activities perceived as high-risk.

Show More