by vague browse
you can tell there are loads of holes in this service:
1. executable customize scripts
2. non-standard mark up languages
3. customizable CSS
4. public accessable server maintenance tool
5. direct POST ability to server without authentication.