Forum Moderators: coopster
MM
<?php
session_start();
$user = $_POST['user'];
$password = $_POST['pass'];
//mysqldetails
require_once("config.php");
$SQL = "SELECT * FROM account WHERE login ='".$user."' AND password = '".$password."'";
$rs = mysql_query($SQL,$conn);
$numRows = mysql_num_rows($rs);
$SQL2 = "SELECT * FROM mobster WHERE login ='".$user."'";
$rs2 = mysql_query($SQL2,$conn);
$numRows2 = mysql_num_rows($rs2);
if($numRows > 0 && $numRows2 > 0){
$_SESSION['loggedIn'] = true;
echo 'login=successin';
}else if($numRows > 0 && $numRows2 == 0){
$_SESSION['loggedIn'] = true;
echo 'login=successnew';
}
?>
' OR ''='
$SQL = "SELECT * FROM account WHERE login ='".$user."' AND password = '[b]' OR ''='[/b]' ";