04-11-2013, 06:32 AM
<b>Change Password</b> <br /><br />
<form action="" method="post">
Old Password : <input type="password" name="oldpassword" /> <br />
New Password : <input type="password" name="newpassword" />
<input type="submit" name="changepass" value="Change Password" /> <br /><br />
<?php
if(isset($_POST[changepass]))
{
$oldpass = anti_injection($_POST[oldpassword]);
$newpass = anti_injection($_POST[newpassword]);
if($oldpass&&$newpass)
{
$conns22 = new mysqli($ip,$sqluser,$sqlpw,$userdb);
$query22 = "SELECT * FROM bg_user WHERE user_id=". $_SESSION[username] ."";
$exec22 = $conns22->query($query22);
$res22 = $exec22->fetch_assoc();
if($res22[truepasswd] == $oldpass)
{
$realpasss = hash("sha256",strtolower($_SESSION[username]).$salt.$newpass);
$conns22d = new mysqli($ip,$sqluser,$sqlpw,$userdb);
$conns22d->query("UPDATE bg_user SET truepasswd=$newpass WHERE user_id=". $_SESSION[username] ."");
$conns22d->query("UPDATE bg_user SET passwd=$realpasss WHERE user_id=". $_SESSION[username] ."");
echo <b>Password changed.</b>;
} else {
echo "<b>Error! Old password isnt correct.</b>";
}
} else {
echo <b>Error! Please enter old and new password.</b>;
}
}
?>
it was fast writing from me

