Guest User

Untitled

a guest
Aug 16th, 2018
119
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.08 KB | None | 0 0
  1. <?php include("header.php");
  2. //username and password sent from form
  3. $myusername=$_POST['user'];
  4. $mypassword=$_POST['pass'];
  5. // To protect MySQL injection (more detail about MySQL injection)
  6. //$myusername = stripslashes($myusername);
  7. //$mypassword = stripslashes($mypassword);
  8. //$myusername = mysql_real_escape_string($myusername);
  9. //$mypassword = mysql_real_escape_string($mypassword);
  10. $myusername = strip_tags(stripslashes($myusername));
  11. $mypassword= strip_tags(stripslashes($mypassword));
  12. $en=enc($mypassword);
  13. $sql="SELECT * FROM $tbl_name WHERE user='$myusername' and pass='$en'";
  14. $result=mysql_query($sql);
  15. // Mysql_num_row is counting table row
  16. $count=mysql_num_rows($result);
  17. // If result matched $myusername and $mypassword, table row must be 1 row
  18. if($count==1){
  19.     // Register $myusername, $mypassword and redirect to file "login_success.php"
  20.     $_SESSION['user']=$myusername;
  21.     $_SESSION['pass']=$mypassword;
  22.     if (headers_sent()) {
  23.         echo "<script type = 'text/javascript'> document.location = 'start.php'; </script>";
  24.     }
  25.     else {
  26.         header("Location: start.php");
  27.     }
  28. }
  29. ?>
Add Comment
Please, Sign In to add comment