Guest User

Untitled

a guest
Oct 3rd, 2018
138
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.79 KB | None | 0 0
  1. <?php
  2. if(isset($_POST['submit_login']) && $user->data['user_id'] == ANONYMOUS)
  3. {
  4.     //form was submitted
  5.     $username = $bvadb->real_escape_string($_POST['username']);
  6.     $password = $bvadb->real_escape_string($_POST['password']);
  7.  
  8.     $q = "SELECT * FROM Users WHERE Username='{$username}' AND Pwd=MD5('{$password}') LIMIT 1";
  9.     $result = $bvadb->Query($q);
  10.    
  11.     if(!$result->num_rows)
  12.     {
  13.         echo "";
  14.         echo '
  15.             <form action="?page=' . $page . '" method="post">
  16.             Wrong username and/or password!
  17.                 <table border=0>
  18.                     <tr><th>Username</th><td>:</td><td><input type="text" value="" name="username" /></td></tr>
  19.                     <tr><th>Password</th><td>:</td><td><input type="password" name="password" /></td></tr>
  20.                 </table>
  21.                 <input type="submit" name="submit_login" value="Login" />
  22.             </form>
  23.         ';
  24.     }
  25.     else
  26.     {
  27.         // log the user in
  28.  
  29.         $old_session_id = $user->session_id;
  30.         $user->session_create($row['FID'], 0, false, $viewonline = true);
  31.  
  32.         //echo "<meta http-equiv=\"refresh\" content=\"0;url=/website/?page={$page}\">";
  33.     }
  34. }
  35. else
  36. {
  37.     if($user->data['user_id'] == ANONYMOUS)
  38.     {
  39.         echo '
  40.             <form action="?page=' . $page . '" method="post">
  41.                 <table border=0>
  42.                     <tr><th>Username</th><td>:</td><td><input type="text" value="" name="username" /></td></tr>
  43.                     <tr><th>Password</th><td>:</td><td><input type="password" name="password" /></td></tr>
  44.                 </table>
  45.                 <input type="submit" name="submit_login" value="Login" />
  46.             </form>
  47.         ';
  48.     }
  49.     else
  50.     {
  51.         $q = "SELECT First_Name, Last_Name, VAID FROM Users WHERE FID={$user->data['user_id']} LIMIT 1";
  52.         $result = $bvadb->Query($q);
  53.         $row = $result->fetch_assoc();
  54.         echo "<div id=\"loginsucces\">Welcome {$row['First_Name']} {$row['Last_Name']}<br />";
  55.         if($row['VAID'] != -1){echo "{$row['VAID']}";}
  56.         echo "</div>";
  57.     }
  58. }
  59.  
  60.  
  61. ?>
Add Comment
Please, Sign In to add comment