I don't think whoever posted that on LEB knows what XSS is. Causing the hostbill login to run a script in your own browser isn't exactly an accomplishment.
If it can run in someone else's, sure; good game. Pat yourself on the back. Doesn't look like it though.