gpt4 book ai didi

php - 密码未被检查

转载 作者:行者123 更新时间:2023-11-29 00:14:28 25 4
gpt4 key购买 nike

当我尝试登录时,它只检查用户名而不检查密码。无论我给它什么密码,它都会接受。如果我在 connect.php 中将 html 回显为 1,它可以正常工作,但重定向不起作用

数据连接.php

<?PHP
@mysql_connect("localhost","root","")
or die("could not connect to mysql");
@mysql_select_db("login")or die("no database");
?>

索引.php

<html> 
<head>
<title>Animated Login</title>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
<link rel="stylesheet" type="text/css" href="login.css">
<script type="text/javascript">
$(function() {
$(".center").animate({
opacity: 100.0,
left: '+=800',
height: 'toggle'
}, 5000, function(){
});
$(".sign_b_btn").live("click",function() {
var u=$("#u").val();
var p=$("#p").val();
if(u==""){
$("#u").css("border-color","red");
$("#un").css("color","red");
$(".error").show().html("Please enter your username.");
$("#p").css("border-color","#606060");
$("#up").css("color","#333333");
}else if(p==""){
$("#u").css("border-color","#606060");
$("#un").css("color","#606060");
$(".error").show().html("Please enter your password.");
$("#p").css("border-color","red");
$("#up").css("color","red");
}else{
dataString = 'u=' + u + '&p=' + p;
$.ajax({
type: "POST",
url: "connect.php",
data: dataString,
cache: false,
success: function(html){
if(html == "" ){
$(".error").show().html("The email or password you entered ois incorrect.");
$("#p,#u").css("border-color","red");
$("#up,#un").css("color","red");
}if(html != ''){
var redirect_url = html;
$(".error").fadeOut(1000);
$("#u").css("border-color","#606060");
$("#un").css("color","#333333");
$("#p").css("border-color","#606060");
$("#up").css("color","#333333");
$(".center").animate({
opacity: 0.25,
left: '+=900',
height: 'toggle'
}, 5000, function() {
$(".done").slideDown(200).html("Welcome "+u);
setTimeout(function(){
var u=$("#u").val("");
var p=$("#p").val("");
window.location=redirect_url;
}, 5000);
});
}
}
});
}
});
});
</script>
</head>
<body>
<div class="main">
<div class="done"></div>
<div class="center">
<div class="title">Login</div>
<div class="error"></div>
<div class="input">
<div class="left" id="un">Username:</div>
<div class="right">
<input type="text" class="log" id="u"></div><div class="c">
</div>
</div>
<div class="input">
<div class="left" id="up">Password:</div>
<div class="right">
<input type="password" class="log" id="p">
</div>
<div class="c"></div>
</div>
<div class="sign_b_btn">
<div class="sign_btn">Sign In</div>
</div>
</div>
</div>
</body>
</html>

连接.php

<?PHP 
include('dataconnect.php');//Your connection to your database

//Get posted values from form
$u=$_POST['u'];
$p=$_POST['p'];

//Strip slashes
$u = stripslashes($u);
$p = stripslashes($p);

//Strip tags
$u = strip_tags($u);
$p = strip_tags($p);

$p=md5($p);
$check = mysql_query("SELECT * FROM user WHERE user ='$u'
AND pass='$p'")or die(mysql_error());
$check = mysql_num_rows($check);
if($check !== "0"){
$results = mysql_query("SELECT user, redirect FROM user WHERE user ='$u'") or die(mysql_error());
while ($row = mysql_fetch_assoc($results)) {
$user=$row['user'];
session_register('user');
$_SESSION['user'] = $user;
echo $row['redirect'];
}
}
?>

最佳答案

我尽力了解您的工作,希望对您有所帮助。

来自您的查询

$results = mysql_query("SELECT user, redirect FROM user WHERE user ='$u'") or die(mysql_error());

WHERE 子句中,您仅将用户名作为验证对象。

也尝试添加密码。

$results = mysql_query("SELECT user, redirect FROM user WHERE user ='$u' AND password ='$p'") or die(mysql_error());

关于php - 密码未被检查,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/23488537/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com