Guest User

Untitled

a guest
Apr 24th, 2018
81
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.50 KB | None | 0 0
  1. <?php
  2. ob_start();
  3. $host="*"; // Host name
  4. $username="*"; // Mysql username
  5. $password="*"; // Mysql password
  6. $db_name="*"; // Database name
  7. $tbl_name="*"; // Table name
  8.  
  9. // Connect to server and select databse.
  10. mysql_connect("$host", "$username", "$password")or die("cannot connect");
  11. mysql_select_db("$db_name")or die("cannot select DB");
  12.  
  13. // Define $myusername and $mypassword
  14. $myusername=$_POST['myusername'];
  15. $mypassword=$_POST['mypassword'];
  16. $approved=$_POST['approved'];
  17. // To protect MySQL injection (more detail about MySQL injection)
  18. $myusername = stripslashes($myusername);
  19. $mypassword = stripslashes($mypassword);
  20. $approved = stipslashes($approved);
  21. $myusername = mysql_real_escape_string($myusername);
  22. $mypassword = mysql_real_escape_string($mypassword);
  23. $approved = mysql_real_escape_string($approved);
  24.  
  25. $sql="SELECT * FROM $tbl_name WHERE username='$myusername' and password='$mypassword' and approved='$approved'";
  26. $result=mysql_query($sql);
  27.  
  28. // Mysql_num_row is counting table row
  29. $count=mysql_num_rows($result);
  30. // If result matched $myusername and $mypassword, table row must be 1 row
  31.  
  32. if($approved != 'yes') {
  33. echo "You haven't been approved as staff! - You can't Login yet.";
  34. }else{
  35.  
  36. if($count==1){
  37. // Register $myusername, $mypassword and redirect to file "login_success.php"
  38. $_SESSION['myusername'] = $myusername;
  39. $_SESSION['mypassword'] = $mypassword;
  40. header("location:login_success.php");
  41. }
  42. else {
  43. echo "Wrong Username or Password";
  44. }
  45. }
  46. ob_end_flush();
  47. ?>
Add Comment
Please, Sign In to add comment