Major PHP Security Flaws Patched

CYBERSPACE — Several major security flaws in the PHP scripting language were successfully patched this week, plugging up holes that could have allowed attackers to gain control of a server that used the server-side language.

“All users of PHP are strongly encouraged to upgrade to one of these releases as soon as possible,” the PHP Group, a community of software developers who put out official releases of the scripting language, said on its website.

PHP: Hypertext Preprocessing, which allows web pages to generate dynamic content and interact with databases, is often used by bloggers and content management applications.

The new patched versions of PHP, 4.3.10 and 5.0.3, available on the PHP Group’s website address a list of six bugs, including several serious security flaws, which was announced last week by the Hardened-PHP team.

Among the problems mentioned in the group’s list were two errors with the language’s variable unserializer that allowed attackers to execute arbitrary code and to craft strings that could pass execution to shellcode contained within the string itself.

“It is strongly recommended to upgrade to the new PHP releases as soon as possible,” said Hardened-PHP. “A lot of PHP applications expose the easy to exploit unserialize() vulnerability to remote attackers.”

Some of the vulnerable applications built using the scripting languages and identified as vulnerable by the Hardened-PHP group include phpBB2, Invision Board, vBulletin, Woltlab Burning Board 2.x, Serendipity Weblog, phpAds and others.

Bulletin board software phpBB is also currently under attack by the Santy.a worm because of bugs contained within its code that effectively allows SQL injection exploits.

In addition to releasing the vulnerabilities to the PHP-using community, Hardened-PHP also offers its own security-harden version of the language.

Patches for the PHP vulnerabilities are available here.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

XBIZ 2026 Conference to Debut All-New Company Lounges, Community Track

The event website for XBIZ 2026 is now live, offering information about North America’s largest adult industry conference, set to take place Jan. 12-15.

Mymember.site Integrates VR Functionality

Mymember.site has added virtual reality playback capability to its website management platform.

Texas Patti to Launch Fetish Platform 'EmpireDom'

Performer and content creator Texas Patti is launching a new platform for doms and fetish creators, EmpireDom.com.

Ohio AG Threatens Action Against 'Major' Adult Sites Over AV Law

Ohio Attorney General Dave Yost announced today that his office is sending "notice of violation" letters to 19 adult websites for failure to comply with the state's recently enacted age verification law.

Chaturbate Announces 2025 Music Contest Winners

Chaturbate has revealed the winners of its 2025 music competition.

2026 XBIZ Exec Awards Pre-Noms Open With Debut of New 'Impact' Honors

XBIZ is pleased to announce that the pre-nomination period for the 2026 XBIZ Exec Awards, the adult industry’s premier career honor, begins today and runs through Oct. 14.

MYM Rolls Out New Traffic Features for German Creators

German platform MYM has launched a new traffic system for its creators.

Ukrainian Content Creators on Hook for Nearly $10M in Back Taxes

Content creators in Ukraine owe the equivalent of $9.3 million in back taxes, according to the country's State Tax Service.

Eroutique Relaunches Site Through YourPaysitePartner

Eroutique has relaunched its official website through YourPaysitePartner (YPP).

Update: Pornhub Will Not Block Ohio, Despite AV Law

Pornhub parent company Aylo will not block access to its websites in Ohio, despite new state age verification rules that came into effect Sept. 30.

Show More