doujiu6976 2013-07-04 12:10
浏览 70
已采纳

php登录脚本使用数据库

Hello I am working on a log in page, i have the issue that when i enter a username and login the page changes to the echo wrong user name or password.

it does not appear to be going to the login_success.php, this is leading to think the issue is with the sql syntax but i am yet to find an answer as to why. i also thought it may be the if($count==1){ and tried ($count>1){ with no success.

I have searched the net and tried a few different approaches but nothing working. I am new and will look into methods to stop sqlinjection however this site is not live and is only for practice :) this community has been a masive help to my learning thank you to you all in advance

HTML LoginPage.html

<form id=login name="login" action="login.php" method="post">
   <fieldset id=fs>
      <legend>Vault Security Console:</legend>
      <!-- legeng tage creates a header title for the fieldset box, filedset pulls all data in the tag to gether with a box around it. -->
      UserName: <input type="text" name="username"> <br>
      Password: <input type="password" name="password"> <br>
      <input type="submit" value="Login"> <input type="submit" value="Register"> 
   </fieldset>
</form>

php-Login.php

<?php
   // Create connection
   $con=mysqli_connect('172.16.254.111',"user","password","Faults"); //(connection location , username to sql, password to sql, name of db)

   // Check connection
   if (mysqli_connect_errno($con))
   {
    echo "Failed to connect to MySQL: " . mysqli_connect_error();
   }
   //below is the variables from the login form
   $username = $_POST['username'];

   $password = md5(strip_tags($_POST['password']));

   $sql="SELECT * FROM Users WHERE username='.addslashes($username).' and password='.addslashes($password).'";
   $result=mysqli_query($sql);   

   //Mysql_num_row is counting table row
   $count=mysqli_num_rows($result);   

   if($count==1){   
   session_register("username");
     session_register("password"); 
   header('location:login_success.php');
   }
   //if false echo below
   else {
    echo "<H2>Wrong Username or Password</H2>";
   }   
?>
  • 写回答

3条回答 默认 最新

  • duanhu2414 2013-07-04 13:22
    关注

    Try this.

    <?php
      //below is the variables from the login form
      $username = mysqli_real_escape_string($con, $_POST['username']);
      $password = md5($_POST['password']);
    
      $sql="SELECT * FROM Users WHERE username='$username' and password='$password'";
      $result=mysqli_query($sql);   
    ?>
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 删除虚拟显示器驱动 删除所有 Xorg 配置文件 删除显示器缓存文件 重启系统 可是依旧无法退出虚拟显示器
  • ¥15 vscode程序一直报同样的错,如何解决?
  • ¥15 关于使用unity中遇到的问题
  • ¥15 开放世界如何写线性关卡的用例(类似原神)
  • ¥15 关于并联谐振电磁感应加热
  • ¥60 请查询全国几个煤炭大省近十年的煤炭铁路及公路的货物周转量
  • ¥15 请帮我看看我这道c语言题到底漏了哪种情况吧!
  • ¥66 如何制作支付宝扫码跳转到发红包界面
  • ¥15 pnpm 下载element-plus
  • ¥15 解决编写PyDracula时遇到的问题