Please, my login form could not login to user homepage, it display (SELECT * FROM members WHERE email = 'wareez' AND password = 'lord')
and this is the login.php code
<?php
Please, my login form could not login to user homepage, it display (SELECT * FROM members WHERE email = 'wareez' AND password = 'lord')
and this is the login.php code
<?php
//Start session
session_start();
//Array to store validation errors
$errmsg_arr = array();
//Validation error flag
$errflag = false;
//Connect to mysql server
include('SQLConfig.php');
//Function to sanitize values received from the form. Prevents SQL injection
//Sanitize the POST values
$a = $_POST['username'];
$password = $_POST['password1'];
//Input Validations
/*if($login == '') {
$errmsg_arr[] = 'Login ID missing';
$errflag = true;
}
if($password == '') {
$errmsg_arr[] = 'Password missing';
$errflag = true;
}
//If there are input validations, redirect back to the login form
if($errflag) {
$_SESSION['ERRMSG_ARR'] = $errmsg_arr;
session_write_close();
header("location: index.php");
exit();
}*/
//Create query
$qry="SELECT * FROM members WHERE email = '$a' AND password = '$password'";
$result=mysql_query($qry);
echo $qry;
//Check whether the query was successful or not
if($result) {
if(mysql_num_rows($result) > 0) {
//Login Successful
session_regenerate_id();
$member = mysql_fetch_assoc($result);
$_SESSION['SESS_MEMBER_ID'] = $member['id'];
$_SESSION['SESS_FIRST_NAME'] = $member['fname'];
header("location: lol.php");
exit();
}else {
//Login failed
header("location: index.php");
exit();
}
}else {
die("Query failed");
}
?>
and also the registration form submit the data to the database but it did not display user homepage after successful registration and this is the regester.php code:
<?php
session_start();
include('SQLConfig.php');
$fname=$_POST['fname'];
$lname=$_POST['lname'];
$address=$_POST['address'];
$city=$_POST['city'];
$contact=$_POST['contact'];
$emailadd=$_POST['emailadd'];
$password=$_POST['password'];
$gender=$_POST['gender'];
$bday=$_POST['bday'];
mysql_query("INSERT INTO members(fname, lname, address, city, contact, email, password, gender, bday, profilepic, coverphoto)VALUES('$fname', '$lname', '$address', '$city', '$contact', '$emailadd', '$password', '$gender', '$bday', 'profilepic/friends.png', 'coverphotos/cover.png')");
header("location: index.php");
mysql_close($con);
?>
please help me, i have try my best on these code. Please!!!
session_start();
//Array to store validation errors
$errmsg_arr = array();
//Validation error flag
$errflag = false;
//Connect to mysql server
include('SQLConfig.php');
//Function to sanitize values received from the form. Prevents SQL injection
//Sanitize the POST values
$a = $_POST['username'];
$password = $_POST['password1'];
//Input Validations
/*if($login == '') {
$errmsg_arr[] = 'Login ID missing';
$errflag = true;
}
if($password == '') {
$errmsg_arr[] = 'Password missing';
$errflag = true;
}
//If there are input validations, redirect back to the login form
if($errflag) {
$_SESSION['ERRMSG_ARR'] = $errmsg_arr;
session_write_close();
header("location: index.php");
exit();
}*/
//Create query
$qry="SELECT * FROM members WHERE email = '$a' AND password = '$password'";
$result=mysql_query($qry);
echo $qry;
//Check whether the query was successful or not
if($result) {
if(mysql_num_rows($result) > 0) {
//Login Successful
session_regenerate_id();
$member = mysql_fetch_assoc($result);
$_SESSION['SESS_MEMBER_ID'] = $member['id'];
$_SESSION['SESS_FIRST_NAME'] = $member['fname'];
header("location: lol.php");
exit();
}else {
//Login failed
header("location: index.php");
exit();
}
}else {
die("Query failed");
}
?>
and also the registration form submit the data to the database but it did not display user homepage after successful registration and this is the regester.php code:
<?php
session_start();
include('SQLConfig.php');
$fname=$_POST['fname'];
$lname=$_POST['lname'];
$address=$_POST['address'];
$city=$_POST['city'];
$contact=$_POST['contact'];
$emailadd=$_POST['emailadd'];
$password=$_POST['password'];
$gender=$_POST['gender'];
$bday=$_POST['bday'];
mysql_query("INSERT INTO members(fname, lname, address, city, contact, email, password, gender, bday, profilepic, coverphoto)VALUES('$fname', '$lname', '$address', '$city', '$contact', '$emailadd', '$password', '$gender', '$bday', 'profilepic/friends.png', 'coverphotos/cover.png')");
header("location: index.php");
mysql_close($con);
?>
please help me, i have try my best on these code. Please!!!