https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/0002 09.html
This module exploits an option injection vulnerability in the SyntaxHighlight extension of MediaWiki. It tries to create & execute a PHP file in the document root. The USERNAME & PASSWORD options are only needed if the Wiki is configured as private.