rapid7/metasploit-framework

View on GitHub
modules/exploits/unix/webapp/phpmyadmin_config.rb

Summary

Maintainability
A
3 hrs
Test Coverage

Method initialize has 53 lines of code (exceeds 25 allowed). Consider refactoring.
Open

  def initialize(info = {})
    super(update_info(info,
      'Name'           => 'PhpMyAdmin Config File Code Injection',
      'Description'    => %q{
          This module exploits a vulnerability in phpMyAdmin's setup
Severity: Major
Found in modules/exploits/unix/webapp/phpmyadmin_config.rb - About 2 hrs to fix

    Method exploit has 39 lines of code (exceeds 25 allowed). Consider refactoring.
    Open

      def exploit
        # First, grab the session cookie and the CSRF token
        print_status("Grabbing session cookie and CSRF token")
        uri = normalize_uri(datastore['URI'], "/scripts/setup.php")
        response = send_request_raw({ 'uri' => uri})
    Severity: Minor
    Found in modules/exploits/unix/webapp/phpmyadmin_config.rb - About 1 hr to fix

      There are no issues that match your filters.

      Category
      Status