//print_r($_GET); //ini_set('display_errors', 1); //ini_set('display_startup_errors', 1); //error_reporting(E_ALL); session_start(); //print_r($_POST); $username = $_POST["username"]; $password = $_POST["password"]; $submit = $_POST["submit"]; $e = $_GET["e"]; if ($e){ $good[]= "Your password has been reset!"; } //if(isset($_SESSION['id'])){ // header("Location: account.php"); // exit; //} $db = mysqli_connect ("localhost", "pack", "watch3r"); mysqli_select_db ($db, "pack"); //$rememberMe = 1; if($_POST['username'] && $_POST['password']) { // Checking whether the Login form has been submitted $err = array(); // Will hold our errors if(!count($err)) { //$_POST['username'] = mysqli_real_escape_string($db,$_POST['username']); //$_POST['password'] = mysqli_real_escape_string($db, $_POST['password']); // Escaping all input data //$row = mysqli_fetch_assoc(mysqli_query($db, "SELECT id,usr FROM pack_user WHERE usr='{$_POST['username']}'")); //echo $username; //echo $password; $row = mysqli_fetch_assoc(mysqli_query($db, "SELECT id,usr FROM pack_user WHERE usr='{$_POST['username']}' or email='{$_POST['username']}' AND pass='".md5($_POST['password'])."'")); //echo "ROW:" . $row; if($row['usr']) { //echo "Found a Row"; // If everything is OK login session_name('mvgen'); $_SESSION['usr']=$row['usr']; $_SESSION['id'] = $row['id']; $user_id = $row['id']; $session_id = $_COOKIE["PHPSESSID"]; // $_SESSION['rememberMe'] = $rememberMe; // Store some data in the session //echo $_SESSION['id']; $query = "UPDATE pack_user set session_id = '$session_id' WHERE id = '$account_id'"; mysqli_query($db, $query); //setcookie('tzRemember',$_POST['rememberMe']); header("Location: index.php"); exit; } else { $err[] = 'Wrong Password Or Username!'; } } } else { if ($submit){ $err[] = 'All the fields must be filled in!'; } } ?>