Guest User

Untitled

a guest
Dec 26th, 2017
140
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.86 KB | None | 0 0
  1. <?php session_start();
  2. include 'database.php';
  3. $username = mysql_real_escape_string(html_entity_decode($_POST['username']));
  4. $password = mysql_real_escape_string(html_entity_decode($_POST['password']));
  5.  
  6. if ($username&&$password) {
  7. $query = mysql_query("SELECT * FROM brukere WHERE username='$username'");
  8. $numrows = mysql_num_rows($query);
  9.  
  10. if ($numrows!=0) {
  11. while ($row = mysql_fetch_assoc($query)) {
  12. $dbusername = $row['username']; //mysql escape here too?
  13. $dbpassword = $row['password'];
  14. }
  15. //Checks if they match
  16. if ($username==$dbusername&&$password==$dbpassword) {
  17. //Logged in
  18. $_SESSION['username']=$username;
  19. echo 'Authenticating user...';
  20. header('refresh: 3; panel.php');
  21. }
  22. else
  23. echo "Incorrect password!";
  24. }
  25. else
  26. die("That user doesn't exist!");
  27. }
  28. else
  29. die("Please enter a username and a password.");
  30. ?>
Add Comment
Please, Sign In to add comment