Codice PHP:
<?
include("config.php");
$scelta=$_POST['scelta'];
$login=$_POST['login'];
$pwd=$_POST['pwd'];
$login=str_replace(";","",$login);
$login=str_replace(":","",$login);
$login=str_replace(",","",$login);
$login=str_replace("'","",$login);
$login=str_replace("*","",$login);
$login=str_replace("?","",$login);
$login=str_replace("=","",$login);
$login=str_replace("&","",$login);
$login=str_replace("%","",$login);
$login=str_replace("$","",$login);
$login=str_replace("<","",$login);
$login=str_replace(">","",$login);
$pwd=str_replace(";","",$pwd);
$pwd=str_replace(":","",$pwd);
$pwd=str_replace(",","",$pwd);
$pwd=str_replace("'","",$pwd);
$pwd=str_replace("*","",$pwd);
$pwd=str_replace("?","",$pwd);
$pwd=str_replace("=","",$pwd);
$pwd=str_replace("&","",$pwd);
$pwd=str_replace("%","",$pwd);
$pwd=str_replace("$","",$pwd);
$pwd=str_replace("<","",$pwd);
$pwd=str_replace(">","",$pwd);
if(trim($login)=="" OR trim($pwd)==""){
echo "I campi Login e Password devono essere riempiti!";
}
if($scelta=='doc'){
$q = "SELECT * FROM InsegnantiLogin WHERE InsegnantiLogin_Login='$login'";
$query = mysql_query($q) or die(mysql_error());
$password=mysql_result($query,0, "InsegnantiLogin_Password");
if($pwd==$password){
url("Docenti/docenti.php");
}
}
?>