<?Php include("settings/db_connection.php");?>
<html>
<head>
<title>IHA INVENTORY LIST</title>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
</head>
<body>

<?Php
session_start();

if(isset($_POST["submit"])){
	
	$member_name = $_POST["member_name"];
	$member_pass = $_POST["member_pass"];
	
	$sql_check = mysql_query("select * from member where member_name='".$member_name."' && member_pass='".$member_pass."' ") or die(mysql_error());
	$count = mysql_num_rows($sql_check);
	if ($count > 0){
		$show = mysql_fetch_array($sql_check);
		$_SESSION["login"] = true;
		$_SESSION["member_name"] = $member_name;
		$_SESSION["member_pass"] = $member_pass;
		$_SESSION["member_situation"] = $show["member_situation"];

	} else {
	echo "Login Failed";
	}

}

if($_SESSION["login"]){
	echo 'Merhaba hoşgeldiniz <strong>'.$_SESSION["member_name"].'</strong> [<a href=exit.php>EXIT</a>]';
	if($_SESSION["member_situation"] == 1){
		echo '<a href="admin/admin.php">Admin Panel</a>';
	}
}
if(!isset($_SESSION["login"])){
	echo '<form action="" method="post">
	<table>
	<tr>
	<th><strong>Member Name:</strong><th>
	<th><input type="text" name="member_name"><th>
	</tr>
	<tr>
	<th><strong>Member Pass:</strong><th>
	<th><input type="password" name="member_pass"><th>
	</tr>
	<tr>
	<th><th>
	<th><input type="submit" name="submit" value="Enter"><th>
	</tr>
	</table>
	</form>';
}

?>
Bir de böyle deneyin yalnız sql açığına dikkat