change password.php

<html>
<head>
<title>Change Password</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<link href="pwd.css" rel="stylesheet" type="text/css">
<link type="text/css" href="menu.css" rel="stylesheet" />
<script type="text/javascript" src="jquery.js"></script>
<script type="text/javascript" src="menu.js"></script>
</head>

<body>
<style type="text/css">

#menu {
    top:5px;
    margin:0 auto;
    width:80%;
	left: 40px;
}

#copyright {
    margin:100px auto;
    width:80%;
    font:12px 'Trebuchet MS';
    color:#bbb;
    text-indent:20px;
    padding:40px 0 0 0;
}
#copyright a { color:#bbb; }
#copyright a:hover { color:#fff; }
</style>

<!--Header of the page-->

<div class="main1">
  <table width="905" height="120" align="center">
    <tr>
      <td width="232" height="114"><img src="images/OnlyWebLOGO.jpg" width="229" height="100"></td>
      <td width="411"><table align="right" width="289">
          <tr>
            <td rowspan="3"><img src="images/phoneIcon1.jpg" width="23" height="38"></td>
            <td colspan="2"><font color="#0066FF"> 1-800-200-7625 </font> <font size="-1" color="#999999">(Tall Free India)</font></td>
          </tr>
          <tr>
            <td colspan="2"><font color="#0066FF"> +91-22-30797900</font></td>
          </tr>
          <tr>
            <td align="right" >&nbsp; <a href="support/index.php">
              <button id="supportbtn" class="Header_button"><font color="#FFFFFF"><b>Support</b></font></button>
              </a></td>
            <td><a href="support/contact-us.php">
              <button id="contactbtn" class="Header_button"><font color="#FFFFFF"><b>Contact Us</b></font></button>
              </button>
              </a></td>
          </tr>
        </table>
        <p> &nbsp;&nbsp;&nbsp;&nbsp; </p></td>
      <!-- <td width="246"> 
<!-- <table width="246" bgcolor="#CCCCCC" align="right">
<tr>
<td width="189" ><p align="left"><strong>HELLO!</strong></p> </td>
<td width="112"><p align="right"><a href=" "><u>My Account</u></a></p></td>
</tr>
<tr>
<td colspan="2" align="right"><button id="checkkoutbtn" class="checkout_button">Check Out</button> </td>
</tr>

</table>
 --> 
      
      <!-- <!-- </td>
 --></tr>
  </table>
  
  <!-- menu design-->
  <div id="menu" align="center">
    <ul class="menu">
      <li><a href="index.php"><span>Home</span></a> </li>
      <div>
        <ul>
          <div>
            <ul>
              </li>
            </ul>
          </div>
          </li>
        </ul>
      </div>
      </li>
      <li><a href="domain-registration/index.php" class="parent"><span>Get 
        a Domain</span></a>
        <div class="columns two">
          <ul class="one">
            <li><span><b><u><font color="#FFFFFF"> Domain Registration</font></u></b></span></li>
            <br>
            <li><a href="domain-registration/index.php"><span>Domain Name Registration</span></a></li>
            <li><a href="domain-registration/domain-registration-price.php"><span>Domain 
              Name Prices</span></a></li>
          </ul>
          <ul class="two">
            <li><span><b><u><font color="#FFFFFF" >Domain Transfer</font></u></b></span></li>
            <br>
            <li><a href="domain-registration/transfer/index.php"><span>Domain 
              Name Transfer</span></a></li>
          </ul>
        </div>
      </li>
      <!-- Get Hosting Menu -->
      <li><a href="web-hosting/index.php" class="parent"><span>Get Hosting</span></a>
        <div class="columns two">
          <ul class="one">
            <li><a href="web-hosting/index.php"><span>Linux Hosting</span></a></li>
            <li><a href="web-hosting/windows-hosting.php"><span>Windows Hosting</span></a></li>
            <li><a href="web-hosting/wordpress-hosting.php"><span>Wordpress 
              Hosting</span></a></li>
          </ul>
          <ul class="two">
            <li><a href="web-hosting/cms-hosting.php"><span>CMS Hosting</span></a></li>
            <li><a href="web-hosting/ecommerce-hosting.php"><span>Ecommerce 
              Hosting</span></a></li>
          </ul>
        </div>
      </li>
      <!-- Build Website Menu -->
      <li><a href="BuildWebsite/index.php" class="parent"><span>Build a Website</span></a>
        <div class="columns">
          <ul>
            <li><a href="BuildWebsite/index.php"><span>Get a Website Builder Tool</span></a></li>
          </ul>
        </div>
      </li>
      <!-- Get Email Menu -->
      <li><a href="web-hosting/email-hosting.php" class="parent"><span>Get 
        Email</span></a>
        <div class="columns">
          <ul>
            <li><a href="web-hosting/email-hosting.php"><span>Email Hosting</span></a></li>
          </ul>
        </div>
      </li>
      <!--  <li><a href="#"><span>My Account</span></a></li> -->
      <li class="last"><a href="support/contact-us.php"><span>My Account</span></a></li>
    </ul>
  </div>
</div>

<!--main page content--> 

<br>
<br>
<br>
<hr align="center" width="75%" color="#DDDDDD" size="1">
<br>
<form id="changepwd_frm" action="con_change_pwd.php" method="post">
<input type="hidden" name="id" value="<?php echo $_GET['id'];?>">
			<?php
			
$con= mysql_connect("localhost","betaonly_ow","mql4xC1a8FNp");
if(!$con)
{
	die('could not connect: ' . mysql_error());
}

mysql_select_db("betaonly_ow", $con);
$id=$_GET["id"];
//echo $id;

$query="select * from ccs_user_registration";

$result=mysql_query($query) or die ("error in query");
//echo mysql_num_rows($result);
if (mysql_num_rows($result)>0)
{
	$row=mysql_fetch_object($result);
	
}
?>

<table width="485" height="233" align="center" >
  <tr>
    <th width="500" colspan="2"><font color="#FF2424" size="+2">Change Password</font><br>
      <br></th>
  </tr>
  <tr bgcolor="#DFE1E3">
    <td width="140" height="37"><center>
        <label id="domain-name-lbl" ><font size="3">Your Email: </font></label>
      </center></td>
    <td width="246"><input type="text" id="email-txt"  name="email_txt"/>
  </tr>
  <tr>
    <td width="140" height="37"><center>
        <label id="domain-name-lbl" ><font size="3">Current pasword: </font></label>
      </center></td>
    <td width="246"><input type="text" id="current_pwd-txt"  name="current_pwd_txt"/>
  </tr>
  <tr bgcolor="#DFE1E3">
    <td height="34"><center>
        <label id="domain-name-lbl" ><font size="3">New pasword: </font></label>
      </center></td>
    <td><input type="text" id="new-pwd-txt" align="absmiddle" name="new_pwd_txt"/></td>
  </tr>
  <tr >
    <td height="38"><center>
        <label id="domain-name-lbl"><font size="3" >Confirm password: </font></label>
      </center></td>
    <td><input type="text" id="con_pwd-txt" align="absmiddle" name="con_pwd_txt" />
  </tr>
  <tr>
    <td colspan="2"><br>
      <br>
      <p align="center">
        <button id="button" class="All_button"><font color="#FFFFFF"><b>Change Password</b></font></button>
      </p></td>
  </tr>
</table>
</form>
</body>
</html>

con_chenge_pwd.php

<?php
$con= mysql_connect("localhost","betaonly_ow","mql4xC1a8FNp");
if(!$con)
{
	die('could not connect: ' . mysql_error());
}

mysql_select_db("betaonly_ow", $con);
echo @$id=$_POST["id"];

@$email_id=$_POST['email_txt'];
@$current_pwd=$_POST['current_pwd_txt'];
@$new_pwd=$_POST['new_pwd_txt'];
@$con_pwd=$_POST['con_pwd_txt'];

/*$sql1="select user_id from ccs_user_registration where email_address='" .$email_id;
$result = mysql_query($sql1);
*/
$sql = "UPDATE ccs_user_registration SET password='".$new_pwd."', confirm_password='".$con_pwd."' WHERE user_id=".$id;

$query = mysql_query($sql); // Perform the update.
if (!$query) { 

    exit("The update failed.");
   }


echo '<script type="text/javascript"> alert("Update successfull");location.href="index.php";</script>';


?>

i want the user id to change the password but it returns nothing for the $result
please help me
thank u

Dani AI

Generated

Quick diagnosis and what to fix first

The usual reason $id arrives empty here is a name / source mismatch between the form and the processor. The form sets a hidden field from the GET value, but the handling script sometimes reads a different key (or expects GET instead of POST). Make the hidden input name and the exact $_POST key match, and validate that key before using it. Also avoid SELECTing the whole table to find one user — query the user row by its id.

A minimal, correct workflow (and a safe example)

  1. Validate the incoming id (exists and numeric).
  2. SELECT the stored password hash for that id and verify the current password.
  3. If verified, hash the new password and UPDATE the row using a prepared statement.

Example (using PDO + PHP password helpers) — this is a compact illustration of steps to use, not a drop-in for your code:

// prepare, fetch stored hash, verify then update
$stmt = $pdo->prepare('SELECT password_hash FROM ccs_user_registration WHERE user_id = ? LIMIT 1');
$stmt->execute([(int)$_POST['id']]);
$hash = $stmt->fetchColumn();
if ($hash && password_verify($_POST['current_pwd'], $hash)) {
  $stmt = $pdo->prepare('UPDATE ccs_user_registration SET password = ? WHERE user_id = ? LIMIT 1');
  $stmt->execute([password_hash($_POST['new_pwd'], PASSWORD_DEFAULT), (int)$_POST['id']]);
}

Why this matters (security & modern PHP)

Do not concatenate raw values into SQL (that’s what made ’s unquoted suggestion risky). Use prepared statements (PDO/mysqli) and PHP’s password_hash / password_verify for safe storage and verification. Also stop storing a separate confirm_password column and use input type="password" for password fields. (php.net)

Quick debugging tips

If the update still “does nothing”, dump the request (print_r($_POST)), check that the hidden id is set and numeric, and let PDO throw exceptions (ERRMODE_EXCEPTION) so you see errors. If you must maintain old code temporarily: migrate away from ext/mysql — it’s deprecated/removed in modern PHP. (php.net)

Notes tied to earlier replies

’s idea of embedding the id in a hidden field is fine — just keep the name consistent with what the processor expects. ’s LIMIT advice is good in principle; pair it with prepared statements rather than unquoted variables.

Recommended Answers

All 5 Replies

Hey, change

$sql = "UPDATE ccs_user_registration SET password='".$new_pwd."', confirm_password='".$con_pwd."' WHERE user_id=".$id;

to

$sql = "UPDATE ccs_user_registration SET password=$new_pwd, confirm_password=$con_pwd WHERE user_id=$id LIMIT 1";
<form id="changepwd_frm" action="con_change_pwd.php" method="post">
<input type="hidden" name="id" value="<?php echo $_GET['id'];?>">
            <?php

$con= mysql_connect("localhost","betaonly_ow","mql4xC1a8FNp");
if(!$con)
{
    die('could not connect: ' . mysql_error());
}

mysql_select_db("betaonly_ow", $con);
$id=$_GET["id"];
//echo $id;

$query="select * from ccs_user_registration";

$result=mysql_query($query) or die ("error in query");
$row=mysql_fetch_array($result);
$id=$row['id'];
?>

<table width="485" height="233" align="center" >
  <tr>
    <th width="500" colspan="2"><font color="#FF2424" size="+2">Change Password</font><br>
      <br></th>
  </tr>
  <tr bgcolor="#DFE1E3">
    <td width="140" height="37"><center>
        <label id="domain-name-lbl" ><font size="3">Your Email: </font></label>
      </center></td>
    <td width="246"><input type="text" id="email-txt"  name="email_txt"/>
  </tr>
  <tr>
    <td width="140" height="37"><center>
        <label id="domain-name-lbl" ><font size="3">Current pasword: </font></label>
      </center></td>
    <td width="246"><input type="text" id="current_pwd-txt"  name="current_pwd_txt"/>
  </tr>
  <tr bgcolor="#DFE1E3">
    <td height="34"><center>
        <label id="domain-name-lbl" ><font size="3">New pasword: </font></label>
      </center></td>
    <td><input type="text" id="new-pwd-txt" align="absmiddle" name="new_pwd_txt"/></td>
  </tr>
  <tr >
    <td height="38"><center>
        <label id="domain-name-lbl"><font size="3" >Confirm password: </font></label>
      </center></td>
    <td>
<input type="hidden" id="hidId" align="absmiddle" name="hidId" value="<?php echo $id;?>" />
<input type="text" id="con_pwd-txt" align="absmiddle" name="con_pwd_txt" />
  </tr>
  <tr>
    <td colspan="2"><br>
      <br>
      <p align="center">
        <button id="button" class="All_button"><font color="#FFFFFF"><b>Change Password</b></font></button>
      </p></td>
  </tr>
</table>
</form>

con_chenge_pwd.php
<?php
$con= mysql_connect("localhost","betaonly_ow","mql4xC1a8FNp");
if(!$con)
{
    die('could not connect: ' . mysql_error());
}

mysql_select_db("betaonly_ow", $con);

$id=$_POST["hidId"]; 
$email_id=$_POST['email_txt'];
$current_pwd=$_POST['current_pwd_txt'];
$new_pwd=$_POST['new_pwd_txt'];
$con_pwd=$_POST['con_pwd_txt'];

/*$sql1="select user_id from ccs_user_registration where email_address='" .$email_id;
$result = mysql_query($sql1);
*/
$sql = "UPDATE ccs_user_registration SET password='".$new_pwd."', confirm_password='".$con_pwd."' WHERE user_id=".$id;

$query = mysql_query($sql); // Perform the update.
if (!$query) { 

    exit("The update failed.");
   }


echo '<script type="text/javascript"> alert("Update successfull");location.href="index.php";</script>';


?>

<form id="changepwd_frm" action="con_change_pwd.php" method="post">
<input type="hidden" name="id" value="<?php echo $_GET;?>">
<?php

$con= mysql_connect("localhost","betaonly_ow","mql4xC1a8FNp");
if(!$con)
{
die('could not connect: ' . mysql_error());
}

mysql_select_db("betaonly_ow", $con);
$id=$_GET["id"];
//echo $id;

$query="select * from ccs_user_registration where id="$id;

$result=mysql_query($query) or die ("error in query");
$row=mysql_fetch_array($result);
$id1=$row;
?>

<table width="485" height="233" align="center" >
<tr>
<th width="500" colspan="2"><font color="#FF2424" size="+2">Change Password</font><br>
<br></th>
</tr>
<tr bgcolor="#DFE1E3">
<td width="140" height="37"><center>
<label id="domain-name-lbl" ><font size="3">Your Email: </font></label>
</center></td>
<td width="246"><input type="text" id="email-txt" name="email_txt"/>
</tr>
<tr>
<td width="140" height="37"><center>
<label id="domain-name-lbl" ><font size="3">Current pasword: </font></label>
</center></td>
<td width="246"><input type="text" id="current_pwd-txt" name="current_pwd_txt"/>
</tr>
<tr bgcolor="#DFE1E3">
<td height="34"><center>
<label id="domain-name-lbl" ><font size="3">New pasword: </font></label>
</center></td>
<td><input type="text" id="new-pwd-txt" align="absmiddle" name="new_pwd_txt"/></td>
</tr>
<tr >
<td height="38"><center>
<label id="domain-name-lbl"><font size="3" >Confirm password: </font></label>
</center></td>
<td>
<input type="hidden" id="hidId" align="absmiddle" name="hidId" value="<?php echo $id1;?>" />
<input type="text" id="con_pwd-txt" align="absmiddle" name="con_pwd_txt" />
</tr>
<tr>
<td colspan="2"><br>
<br>
<p align="center">
<button id="button" class="All_button"><font color="#FFFFFF"><b>Change Password</b></font></button>
</p></td>
</tr>
</table>
</form>

con_chenge_pwd.php
<?php
$con= mysql_connect("localhost","betaonly_ow","mql4xC1a8FNp");
if(!$con)
{
die('could not connect: ' . mysql_error());
}

mysql_select_db("betaonly_ow", $con);

$id=$_POST["hidId"];
$email_id=$_POST;
$current_pwd=$_POST;
$new_pwd=$_POST;
$con_pwd=$_POST;

/*$sql1="select user_id from ccs_user_registration where email_address='" .$email_id;
$result = mysql_query($sql1);
*/
$sql = "UPDATE ccs_user_registration SET password='".$new_pwd."', confirm_password='".$con_pwd."' WHERE user_id=".$id;

$query = mysql_query($sql); // Perform the update.
if (!$query) {

exit("The update failed.");
}


echo '<script type="text/javascript"> alert("Update successfull");location.href="index.php";</script>';


?>

Can people please use the f% (CODE) tags around the code they paste?? Not that hard.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.