Guest User

Untitled

a guest
Jun 19th, 2018
108
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.60 KB | None | 0 0
  1. <?php
  2.  
  3. if(!defined('_VALID_ACCESS')) die('direct access is not allowed.');
  4. include('includes/connect.php');
  5.  
  6. function login($username, $password)
  7. {
  8. $username = trim($username);
  9. $password = trim($password);
  10. echo $username;
  11. echo $password;
  12. $login_sql = "SELECT * FROM user WHERE user = '".($username)."'
  13. AND pass = '".(md5($password))."'";
  14. $login_result = $mysqli->query($login_sql) or die(mysqli_error());
  15. $row=$login_result->fetch_row();
  16. if($row[0] == 1)
  17. {
  18. return true;
  19. }
  20. else
  21. {
  22. return false;
  23. }
  24. }
  25. ?>
  26.  
  27. <?php
  28. $db_name = "coolmates";
  29. $db_server = "localhost";
  30. $db_user = "justron";
  31. $db_pass = "Justron9004";
  32.  
  33. $mysqli = new MySQLi($db_server, $db_user, $db_pass, $db_name) or die(mysqli_error());
  34.  
  35. ?>
  36.  
  37. function login($username, $password)
  38. {
  39. global $mysqli;
  40. $username = trim($username);
  41. $password = trim($password);
  42. echo $username;
  43. echo $password;
  44. $login_sql = "SELECT * FROM user WHERE user = '".($username)."'
  45. AND pass = '".(md5($password))."'";
  46. $login_result = $mysqli->query($login_sql) or die(mysqli_error());
  47. $row=$login_result->fetch_row();
  48. if($row[0] == 1)
  49. {
  50. return true;
  51. }
  52. else
  53. {
  54. return false;
  55. }
  56. }
  57.  
  58. $login_result = $mysqli->query("SELECT COUNT(1) result FROM user WHERE user = ? AND pass = ?");
  59. $login_result->bind_param("ss", $username, md5($password));
  60. $login_result->execute();
  61. $login_result->bind_result($count);
  62. $login_result->fetch();
  63. if ($count == 1) {
  64. // success
  65. } else {
  66. // failure
  67. }
  68.  
  69. ' or true or '' = '
  70.  
  71. select 'hello' = '' or true or '' = '' and 'world' = '1';
Add Comment
Please, Sign In to add comment