<?php
session_start();
if(empty($_SESSION['UID']))
{
if(isset($_POST['login_password']))
{
$result = DB::Query("SELECT * FROM Users WHERE Username='".addslashes($_POST['login_username'])."' AND Password='".MD5($_POST['login_password'])."'");
if(mysql_num_rows($result) > 0)
{
$row = mysql_fetch_array($result);
session_register("UID");
session_register("FullName");
session_register("Admin");
$_SESSION['UID'] = $row['ID'];
$_SESSION['FullName'] = $row['FullName'];
$_SESSION['Admin'] = $row['Admin'];
}
else
{
$error = "An error occurred. Username or password incorrect";
}
}
}
if(empty($_SESSION['UID']))
{
?>
<html>
<head>
<link rel="stylesheet" href="css/main.css">
<title>PHP-Comics : Area Resitricted</title>
</head>
<body>
<h1>Please Log In</h1>
<?=$error; ?>
<form action="" method="post">
<table>
<tr>
<td>Username:</td>
<td><input type="text" name="login_username" /></td>
</tr>
<tr>
<td>Password:</td>
<td><input type="password" name="login_password" /></td>
</tr>
<tr>
<td colspan="2">
<input type="submit" value="Login" />
</td>
</tr>
</table>
</form>
</body>
</html>
<?php
exit(0);
}
?>