Advertisement
Guest User

Untitled

a guest
Aug 14th, 2017
68
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.91 KB | None | 0 0
  1. <?php
  2. ob_start();
  3.  
  4. // Connect to MySQL
  5. $location=localhost;
  6. $dbusr=sj;
  7. $dbpass=hidden;
  8. $db=sj_mcwusers;
  9. $tbl_name=admins;
  10.  
  11. mysql_connect("$location","$dbusr","$dbpass")or die("Failed to Connect");
  12. mysqL_select_db("$db")or die("Cannot select DB");
  13.  
  14.  
  15. // Get the username and password
  16. $preuser=$_POST['user'];
  17. $prepass=$_POST['pass'];
  18.  
  19.  
  20. // Sanitize input to prevent injection
  21. $pass = mysql_real_escape_string($prepass);
  22. $user = mysql_real_escape_string($preuser);
  23.  
  24. // Does the user exist?
  25.  
  26. $q="SELECT * FROM $tbl_name WHERE username='$user' AND password='$pass'";
  27. $result=mysql_query($sql);
  28. $numrow = mysql_numrows($result);
  29. if ($numrow != 1) {
  30. echo("Invalid username or password.");
  31. }
  32.  
  33.  
  34. else {
  35. $res = mysql_fetch_array($result);
  36.  
  37. $_SESSION['level'] = $res['admlevel'];
  38. $_SESSION['id'] = $res['id'];
  39. $_SESSION['user'] = $res['user'];
  40. echo("login success");
  41.  
  42.  
  43. // End the OB
  44. ob_end_flush();
  45. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement