Te li osto direttamente

QUESTO E' LOGIN.PHP
Ho cercato di omettere parte del superfluo.

<td><form name="form" method="post" action="login2.php">
<?php session_start();
print "Inserire Login e Password

";

?> </td>
</tr>
<tr>
<td>Login:</td>
<td><div align="right">
<input name="username" type="text" id="username" size="15" maxlength="20">
</div></td>
</tr>
<tr>
<td>Password</td>
<td><div align="right">
<input type="password" name="password" size="15" maxlength="20">
</div></td>
</tr>
<tr>
<td style="text-align:center"></td>
<td style="text-align:center"><div align="right">
<input name="Submit" type="submit" class="submit" value="login">
</div></td>
</tr>
</table>
</form></td>


QUESTO E' LOGIN2.PHP
Codice PHP:
$uname = $_POST['username']; 
$passw = $_POST['password']; 

    $query = mysql_query("SELECT * FROM utenti WHERE username='$uname' and password='$passw' "); 
    $num = mysql_num_rows($query); 
     
   if ($num != 0) { 
     
        $row=mysql_fetch_array($query); 
        $_SESSION['login_staff'] = "ok"; 
        $_SESSION['login_staff_utente'] = "$row[username]"; 
        $_SESSION['login_staff_tipo'] = "$row[tipo]"; 
        $_SESSION['login_staff_cognome'] = "$row[cognome]"; 
        $_SESSION['login_staff_nome'] = "$row[nome]"; 
        header("Location: index.php"); 
        exit;                  
    } else { 
       
       ?>
        <input name="num" type="text" id="num" value="<?php $num ?> ">
        
        <?php
        $_SESSION
['login_staff'] = "no"
        
$_SESSION['login_staff_utente'] = ""
        
$_SESSION['login_staff_tipo'] = "";  
        
$_SESSION['errore'] = "Login e/o Password errati".
        
header("Location: login.php?msg=Login e/o Password erratti"); 
        exit;  
        } 
?>