Forum Moderators: coopster
$sql = "SELECT id FROM tblfranchiseinfo WHERE fousername = '$_SESSION[myusername]' and fopassword = '$mypassword'";or
$myusername = $_SESSION["myusername"];or even
$sql = "SELECT id FROM tblfranchiseinfo WHERE fousername = '$myusername' and fopassword = '$mypassword'";
$sql = "SELECT id FROM tblfranchiseinfo WHERE fousername = '".$_SESSION["myusername"]."' and fopassword = '$mypassword'";
If you have suggestions on how to protect it from SQL injections
SELECT * FROM mytable where field_1 = param_1