You should always gather as much information on the target as possible.
For example, if it's hosted on shared hosting (which i suspect in this case) then there's a big chance that another webpage hosted on that server is vulnerable. Hack that site, root the box, edit the html page, voilà ! you just pwnt the html page and a handful of other ones..
tl;dr: Find out everything you can before trying to hack it.