Skip to content

Instantly share code, notes, and snippets.

@edisetiawan
Created December 8, 2015 15:32
Show Gist options
  • Save edisetiawan/2a1efdb05b957ef7f4c9 to your computer and use it in GitHub Desktop.
Save edisetiawan/2a1efdb05b957ef7f4c9 to your computer and use it in GitHub Desktop.
<?php
include('inc-db.php');
$username=$_POST['username'];
$password=$_POST['password'];
$sql_check="select * from admin where
admin_username='".$username."'";
$result = mysql_query($sql_check);
$getUser = mysql_num_rows($result);
//print_r($getUser); die();
$getDataUser = mysql_fetch_array($result);
if ($getUser === 1)
{
if (password_verify($password,$getDataUser['admin_password']))
{
session_start();
$_SESSION['username']=$getDataUser['admin_username'];
header('location: admin_area.php');
//echo "Is Valid User";
}
else
{
echo "Invalid User";
}
}
else
{
echo "Invalid User";
}
?>
@covit1
Copy link

covit1 commented Apr 12, 2021

SELECT * FROM users WHERE username = '$_POST'user1′ AND 1=1# AND password = '$_POST'

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment