I've borrowed the code from elsewhere and altered for our needs... but I think we should think about getting something off the ground soon.
Site is below:
SQL db just needs importing, and login details changed in "header.php" if I remember rightly.
I think this, and another similar site with different vuln points in the site, maybe RFI/LFI for the other team. Plus some SSH/software exploitation challenges would be a good start for a CTF. Challenge to deface or get db or something or win automatically by getting root.