Advertisement
Guest User

Untitled

a guest
Sep 19th, 2017
80
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.66 KB | None | 0 0
  1. <?php
  2. session_start();
  3. /*##############################################
  4. # Shadowcms #
  5. # © 2011 #
  6. # Devbest #
  7. # #
  8. ##############################################
  9. */
  10. //Database Info
  11. $dbhost = "localhost"; // Default is localhost
  12. $dbname = "shadowcms"; //Database
  13. $dbuser = "root"; // Default is root
  14. $dbpass = "pass"; //phpmyadmin password
  15. $dbtable = "users"; //Database table
  16.  
  17. // Connecting to database yay!
  18. mysql_connect($dbhost, $dbuser, $dbpass) or die ("Could not connect: ". mysql_error());
  19. mysql_select_db($dbname) or die (mysql_error());
  20.  
  21. if (isset($_POST['username']) && isset($_POST['password']))
  22. {
  23. $username = $_POST['username']; $password = $_POST['password'];
  24. echo 'They are being passed<br />';
  25. }
  26. else
  27. {
  28. echo 'The post variables are not being passed';
  29. }
  30. echo '$_POST[\'password\'] = '.$_POST['password'].' and $_POST[\'username\'] = '.$_POST['username'];
  31. // Protect our login page from SQL injections
  32. $username = stripslashes($username);
  33. $password = stripslashes($password);
  34. $username = mysql_real_escape_string($username);
  35. $password = mysql_real_escape_string($password);
  36.  
  37. $sql = "SELECT * FROM $table WHERE username = `".$username."` AND password = `".$password."`";
  38. $result = mysql_query($sql);
  39.  
  40. if(!$result)
  41. {
  42. die ('Invalid query: '. mysql_error());
  43. }
  44.  
  45. $count = mysql_num_rows($result);
  46. if($count == 1) {
  47. session_register("username");
  48. session_register("password");
  49. header("Location: me.php");
  50. }
  51. else
  52. {
  53. echo "Wrong username or password";
  54. }
  55. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement