Kloxo HostInABox 575 - useradd string in the process list



DESCRIPTION


When new accounts are created via Kloxo, the useradd string appears in the process list, complete with password of the user.



IMPACT


Local users could obtain the password hashes for newly created accounts, which would potentially allow them to access the accounts, given that the hash could be cracked in sufficient time.