what is wrong here?
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
</head>
<body>
<?php
session_start();
$user = $_SESSION ['username'];
if ($user)
{
//user is logged in
if ($_POST['submit'])
{
$oldpassword = md5($_POST['oldpassword']);
$newpassword= md5($_POST['newpassword']);
$repeatnewpassword = md5($_POST['repeatnewpassword']);
//connect db
$connect = mysql_connect("localhost","webdesigning1","") or die ("couldnt connect to mysql data base ");
mysql_select_db("phplogin") or die("couldnt find db") ;
$queryget = mysql_query("SELECT password FROM users WHERE username ='$user'") or die("query didnt work");
$row=mysql_fetch_assoc($queryget);
$oldpassworddb=$row['password'];
echo $oldpassworddb."<br>";
//check pass againest db
echo $oldpassword."<br>";
if ($oldpassword==$oldpassworddb)
{
if ($newpassword==$repeatnewpassword)
{
$querychange = mysql_query("UPDATE users SET password='$newpassword' WHERE username='$user'");
session_destroy();
die("Your password has been changed.<a href='/webdesigning1/index.php'>Return</a>");
}
else
die ("new passwords don't match!");
}
else
die ("old password dosent match!");
}
else
echo "
<form action='/webdesigning1/changepassword.php' method='POST'>
old password:<input type='text' name='oldpassword'><p>
new password:<input type='password' name='newpassword'><br>
repeat new password:<input type='password' name='repeatnewpassword'><br>
<input type='submit' name='submit' value='change password'> <p>
</form>
";
}
else
die
("You must be logged in to change the password")
?>
</body>
</html>
when i give correct password & new and repeat new passwords it displays this
123456
e10adc3949ba59abbe56e057f20f883e
old password dosent match!