<?php
session_start();
include 'connect.php';
<?php
session_start();
include 'connect.php';
if(isset($_POST['submit'])) {
//$username = $_POST['username'];
$password = md5($_POST['currentpassword']);
$newpassword = md5($_POST['newpassword']);
$confirmnewpassword = md5($_POST['newpassword1']);
$user_id = $_SESSION['user_id'];
var_dump($user_id);
$sql = "SELECT * FROM user WHERE user_id=$user_id ";
var_dump($sql);
mysql_select_db($dbname) or die(mysql_error());
$result = mysql_query($sql);
//mysql_fetch_assoc($result);
while($data = mysql_fetch_assoc($result) ){
$userPassword = $data['password'];
}
if($password == $userPassword) {
if($newpassword == $confirmnewpassword){
$sql = "UPDATE user SET password = '$newpassword WHERE user_id = $user_id";
{
if(!$result) {
echo 'password successfully changed';
}
else{
'new password and password must be the same';
}
}
}
}
}
?>