1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
|
<?php
$Serveur = "localhost"; $User = "root"; $Mdp = ""; $MaBase = "mysql";
$username = 'FoxLeRenard';
$password = "' OR ''='";
$link=mysql_connect($Serveur,$User,$Mdp) OR die('Erreur connexion ');
$Flag2=mysql_select_db($MaBase) OR die('Erreur connexion ');
/* $username=mysql_real_escape_string($username, $link);
$password=mysql_real_escape_string($password, $link); */
$query ="select * from fi_user WHERE UserNom = '$username' AND UserPas = '$password' ";
echo ("".$query."<br />");
$result=mysql_query($query, $link);
while ($row=mysql_fetch_array($result))
{
$UserNom= stripslashes($row['UserNom']);
$UserMail= stripslashes($row['UserMail']);
$UserPas= stripslashes($row['UserPas']);
echo ("xxxxxxx".$UserMail."xxxxx<br />");
}
mysql_close();
?>
</body></html> |