Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-0342
http://www.securityfocus.com/bid/4181
http://www.iss.net/security_center/static/8305.php