dude theres only PHP FILES --' im not here to scam. (next time take it or leave it.)
http://www.virustotal.com/file-scan/report.html?id=f71120626c432ef1107f82b6b9e4f7efe741feddcbabc22cb0a0378ddc090281-1323716013#
someone asked me on Ota... to release an Automatic VIP (to make it "pay and get rank" you need to add your script" but actualy it's free
my cms based on ReVCMS most developped cms plugins i have a Rare/badge/bots shop + VIP automatic etc...
to start i will release the VIP Plugin:
if you...
sorry but i just found a simpl and easy xss fail :s
Just go to ur hotel and type in ur mission
<script>ALERT('fail xss detected by Spartak')</script>
and come back to ur staff page....wow
to fixe that add a simple htmlspecialchar befor username etc...