i have this peice of code :
<?php
$dbhost=\"localhost\";
$dbname=\"prima\";
$dbusername=\"\";
$dbuserpassword=\"\";
$default_dbname=\"prima\";
$MYSQL_ERRNO = \'\';
$MYSQL_ERROR = \'\';
$new_win_width = 600;
$new_win_height = 400;
$register_script = \"./register.php\";
function html_header() {
global $new_win_width, $new_win_height;
?>
<HEAD>
<SCRIPT LANGUAGE=\"JavaScript\" TYPE=\"text/javascript\">
<!--
function open_window(url) {
var NEW_WIN = null;
NEW_WIN = window.open (\"\", \"RecordViewer\", \"toolbar=no,width=\"+<?php echo $new_win_width ?>+\",height=\"+<?php echo $new_win_height?>+\",directories=no,status=no,scrollbars=yes,resize=no,menubar=no\");
NEW_WIN.location.href = url;
}
//-->
</SCRIPT>
<TITLE>User Record Viewer</TITLE>
</HEAD>
<BODY>
<?php
}
function html_footer() {
?>
</BODY>
<?php
}
function db_connect($dbname=\'\') {
global $dbhost, $dbusername, $dbuserpassword, $default_dbname;
global $MYSQL_ERRNO, $MYSQL_ERROR;
$link_id = mysql_connect($dbhost, $dbusername, $dbuserpassword);
if(!$link_id) {
$MYSQL_ERRNO = 0;
$MYSQL_ERROR = \"Connection failed to the host $dbhost.\";
return 0;
}
else if(empty($dbname) && !mysql_select_db($default_dbname)) {
$MYSQL_ERRNO = mysql_errno();
$MYSQL_ERROR = mysql_error();
return 0;
}
else if(!empty($dbname) && !mysql_select_db($dbname)) {
$MYSQL_ERRNO = mysql_errno();
$MYSQL_ERROR = mysql_error();
return 0;
}
else return $link_id;
}
function sql_error() {
global $MYSQL_ERRNO, $MYSQL_ERROR;
if(empty($MYSQL_ERROR)) {
$MYSQL_ERRNO = mysql_errno();
$MYSQL_ERROR = mysql_error();
}
return \"$MYSQL_ERRNO: $MYSQL_ERROR\";
}
function auth_user($adminUsername, $adminPass)
{
global $default_dbname, $administrators;
$link_id = db_connect($default_dbname);
$query = \"SELECT username FROM $administrators
WHERE adminUsername = \'$adminUsername\'
AND adminPass = password(\'$adminPass\')\";
$result = mysql_query($query);
if (!@mysql_num_rows($result)) return 0;
else
{
$query_data = mysql_fetch_row($result);
return $query_data[0];
}
}
function login_form()
{
global $PHP_SELF;
?>
<HEAD>
<TITLE>Login</TITLE>
</HEAD>
<BODY link=\"#008000\" bgcolor=\"#336699\" text=\"#FFFFFF\">
<p align=\"center\"><br></p>
<p align=\"center\"><u><font size=\"5\">PRImA ONLINE DATABASE</font></u></p>
<p align=\"center\"><br></p>
<p align=\"left\"><br><u><font size=\"4\">Administrators Login</font></u></p>
<p align=\"justify\"><br><br>
<p align=\"center\">
<FORM METHOD=\"POST\" ACTION=\"<? echo $PHP_SELF ?>\">
<DIV ALIGN=\"CENTER\"><CENTER>
<H3>Please Log In specifying your username and your password.</H3>
<TABLE BORDER=\"1\" WIDTH=\"200\" CELLPADDING=\"2\">
<TR>
<TH WIDTH=\"18%\" ALIGN=\"RIGHT\" NOWRAP>Username</TH>
<TD WIDTH=\"82%\" NOWRAP>
<INPUT TYPE=\"TEXT\" NAME=\"adminUsername\" SIZE=\"8\">
</TD>
</TR>
<TR>
<TH WIDTH=\"18%\" ALIGN=\"RIGHT\" NOWRAP>Password</TH>
<TD WIDTH=\"82%\" NOWRAP>
<INPUT TYPE=\"PASSWORD\" NAME=\"adminPass\" SIZE=\"8\">
</TD>
</TR>
<TR>
<TD WIDTH=\"100%\" COLSPAN=\"2\" ALIGN=\"CENTER\" NOWRAP>
<INPUT TYPE=\"SUBMIT\" VALUE=\"LOGIN\" NAME=\"Submit\">
</TD>
</TR>
</TABLE>
</CENTER></DIV>
</FORM>
</BODY>
<?
}
session_start();
if (!isset($adminUsername))
{
login_form();
exit;
}
else
{
session_register(\"adminUsername\", \"adminPass\");
$adminFullname = auth_user($adminUsername, $adminPass);
if (!$adminFullname)
{
session_unregister(\"adminUsername\");
session_unregister(\"adminPass\");
echo \"Authorization failed.\" .
\"You must enter a valid username and password. \" .
\"Click on the following link to try again.<BR>\n\";
echo \"<A HREF=\\"$PHP_SELF\\">Login</A><BR>\";
echo \"If you\'re not a member yet, click \" .
\"on the following link to register.<BR>\n\";
echo \"<A HREF=\\"$register_script\\">Membership</A>\";
exit;
}
else echo \"Welcome, $adminFullname\";
}
?>
and when i am running it it appears me illegal operation in php.exe
This is a login page of an administrator that i already have done the register.php file which submits successfully the data in my database.
I would appreaciate if you could help me to sort that out.