Search for PHP 5 and download the latest version.
Also search for IIS Recommended Configuration and install that a long with URL rewrite 2.0, should solve the problem(hopefully)
Xampp is not more secure so please don't tell people to use it. The fact that it's more popular is false. Xampp should only be used if you know what you are doing. There is security risks like webdev folder, folders in htdocs are not protected unless you fix it, and phpmyadmin is exploitable unless patched
The dealio with webdav. Just editing files is done using a "PHP Shell" a script that allows the user to go into the webdav after uploading a file using the webdav exploite and navigating through all of the files on your VPS.