diff options
Diffstat (limited to 'web/html')
-rw-r--r-- | web/html/index.php | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/web/html/index.php b/web/html/index.php index 5814fec..033a69e 100644 --- a/web/html/index.php +++ b/web/html/index.php @@ -19,7 +19,10 @@ if (isset($_REQUEST["user"]) || isset($_REQUEST["pass"])) { if (!$login_error) { # Try and authenticate the user # - $dbh = db_connect(); + + #md5 hash it + $_REQUEST["pass"] = md5($_REQUEST["pass"]); + $dbh = db_connect(); $q = "SELECT ID, Suspended FROM Users "; $q.= "WHERE Username = '" . mysql_escape_string($_REQUEST["user"]) . "' "; $q.= "AND Passwd = '" . mysql_escape_string($_REQUEST["pass"]) . "'"; |