dear friends,
i allready written code for PHP registration and login forms . i am worried about attacks from user unwanted data entry.My code is below.
<?php
include"conn.php";
if(isset($_POST['login'])){
$uname= $_POST['username'];
$pword= $_POST['password'];
$uname =real_escape_string($uname);
$pword= real_escape_string($pword);
$sql="SELECT * FROM login1 WHERE L1='$uname' AND L2='$pword'";
$result=$conn->query($sql);
if($result->num_rows>0){
echo("welcome");
}
else {
echo ("invalid username"."<br>");
}
}
?>
i got undefined function error in $uname=real_escape_string($uname);..plz suggest me..