<?php
if ($_POST['email'] != "") {
include_once "connect_to_mysql.php";
$email = $_POST['email'];
$pass = $_POST['pass'];
$email = strip_tags($email);
$email = mysql_real_escape_string($email);
$email = eregi_replace("`", "", $email);
$pass = md5($pass);
$sql = mysql_query("SELECT * FROM x WHERE email='$email' AND Passwort='$pass' AND email_activated='1'");
$login_check = mysql_num_rows($sql);
if($login_check > 0){
while($row = mysql_fetch_array($sql)){
$id = $row["id"];
session_register('id');
$_SESSION['id'] = $id;
$Vorname = $row["Vorname"];
session_register('Vorname');
$_SESSION['Vorname'] = $Vorname;
$email = $row["email"];
session_register('email');
$_SESSION['email'] = $email;
mysql_query("UPDATE x SET last_log_date=now(), Logins=Logins + 1 WHERE id='$id'");
mysql_query("DELETE FROM Logins WHERE (NOW() - INTERVAL 1 DAY) > Datum AND ID='$id'");
mysql_query("SELECT COUNT(ID) FROM Logins WHERE ID='$id'");
$count = mysql_fetch_assoc();
var_dump($count);
if ($count [val] <3){
mysql_query("INSERT INTO y (Datum, ID) VALUES (now(),'$id') ");
mysql_query("UPDATE x SET punkte=punkte + 1 WHERE id='$id'");
}
}
exit();
}
}
?>
<?php echo var_dump($count) ?>
<body>
<form id="email" name="email" method="post" action=""><input type="text" name="email" id="email" /></form>
<form id="pass" name="pass" method="post" action=""><input type="password" name="pass" id="pass" /></form>
<form id="submit" name="submit" method="post" action=""><input type="submit" name="submit" id="submit" value="Senden" /></form>
</body>