ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.
https://exchange.xforce.ibmcloud.com/vulnerabilities/29113
http://www.securityfocus.com/bid/20152
http://www.securityfocus.com/archive/1/446719/100/0/threaded