Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Judge Dismisses Last NCOSE-Backed Suit Over Kansas AV Law

A federal judge on Monday dismissed a lawsuit alleging that adult site SuperPorn violated Kansas’ age verification law, citing lack of jurisdiction after similarly dismissing two related cases earlier this year.

ASACP Rolls Out 'Restricted to Adults' Labeling Tool Updates

The Association of Sites Advocating Child Protection (ASACP) has updated its Restricted to Adults (RTA) labeling system.

Federal AV Proposal Scores Minor Win in House but Remains in Doubt

A newly announced bipartisan agreement in the U.S. House of Representatives Committee on Energy and Commerce may soon bring a proposed federal age verification law before the full House, but the measure continues to face an uphill battle.

Arizona Governor Vetoes 'Protect Act' With New Consent Provisions

Arizona Governor Kate Hobbs on Friday vetoed HB 2133, the “Protect Act,” which would have imposed new requirements for adult content uploaded online.

Brazil Begins Monitoring 18 Adult Sites for AV Compliance

Brazil’s National Data Protection Authority (ANPD) is now monitoring 18 high-traffic adult websites for compliance with the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires such sites to age-verify users located in Brazil.

Ofcom Fines First Time Videos $100,000 for AV Noncompliance

U.K. media regulator Ofcom on Thursday imposed a fine of 80,000 pounds (more than $100,000) against First Time Videos, which operates FTVGirls.com and FTVMilfs.com, for failing to implement age checks required for compliance with the Online Safety Act.

Curves Ahead: How BBW Creators are Turning Differentiation Into Competitive Advantage

For centuries, curves have been celebrated as a symbol of beauty, sensuality and power. From the soft opulence of Rubens paintings to the glamorous silhouettes of pinup icons, fuller figures have long occupied a place in art, fashion and fantasy.

Woodhull Freedom Foundation to Host Virtual 'Pride' Edition of 'Fact Checked' Series

Woodhull Freedom Foundation is hosting a Pride Month virtual edition of its series “Fact Checked by Woodhull.”

'InMelanin' Relaunches Through PAYSITE

InMelanin.com has officially relaunched through PAYSITE.

Pearl Industry Network Partners With Takedown Piracy

Industry trade group Pearl Industry Network (PiN) has officially partnered with Takedown Piracy.

Show More