<?php //include ("../../db.inc.php");
include($_SERVER['DOCUMENT_ROOT'].'/wwincludes/db.inc.php');
if (!isset($_SERVER['PHP_AUTH_USER']))
{
Header ("WWW-Authenticate: Basic realm=\"Admin Page\"");
Header ("HTTP/1.0 401 Unauthorized");
exit();
}
else {
if (!get_magic_quotes_gpc()) { //mysql_real_escape_string ШЇШ§Щ„Ш© Щ„ШЩ…Ш§ЩЉШ© Ш§Щ„Щ…ШЄШєЩЉШ±Ш§ШЄ Щ‚ШЁЩ„ Ш§ШЇШ®Ш§Щ„Щ‡Ш§ Щ„Щ‚Ш§Ш№ШЇШ© Ш§Щ„ШЁЩЉШ§Щ†Ш§ШЄ
$_SERVER['PHP_AUTH_USER'] = mysql_real_escape_string($_SERVER['PHP_AUTH_USER']);
$_SERVER['PHP_AUTH_PW'] = mysql_real_escape_string($_SERVER['PHP_AUTH_PW']);
}
$query = "SELECT pass FROM admin WHERE user='".$_SERVER['PHP_AUTH_USER']."'";
$lst = @mysql_query($query);
if (!$lst)
{
Header ("WWW-Authenticate: Basic realm=\"Admin Page\"");
Header ("HTTP/1.0 401 Unauthorized");
exit();
}
if (mysql_num_rows($lst) == 0)
{
Header ("WWW-Authenticate: Basic realm=\"Admin Page\"");
Header ("HTTP/1.0 401 Unauthorized");
exit();
}
$pass = @mysql_fetch_array($lst);
if ($_SERVER['PHP_AUTH_PW']!= $pass['pass'])
{
Header ("WWW-Authenticate: Basic realm=\"Admin Page\"");
Header ("HTTP/1.0 401 Unauthorized");
exit();
}
}
ошибка
пароль будет передан незашифрованным