yep but i cant seem to figure out where i have been looking at this code all day and nothing seems to look wrong (to me)
<?php
session_start();
ini_set('session.bug_compat_42',0);
ini_set('session.bug_compat_warn',0);
$host="localhost"; // Host name
$username="phpuser"; // username
$password="phpuser"; // password
$db_name="phpsite"; // Database name
$tbl_name="users"; // Table name
// Replace database connect functions depending on database you are using.
mysql_connect("$host", "$username", "$password");
mysql_select_db("$db_name");
//submitting query
// username and password sent from form
//NEVER Remove the mysql_real_escape_string. Else there could be an Sql-Injection!
$UsersID=mysql_real_escape_string($_POST['UsersID']);
$U_Password=mysql_real_escape_string($_POST['U_Password']);
$sql="SELECT UsersID,U_YearID FROM users WHERE UsersID='$UsersID' and U_Password='$U_Password'";
//echo $sql;
$result=mysql_query($sql);
//checking results
// Replace counting function based on database you are using.
$count=mysql_num_rows($result);
// If result matched $myusername and $mypassword, table row must be 1 row
//Direct Userbased on result
if($count==1){
// Register $UsersID, $U_Password and redirect to file "login_success.php"
$_SESSION['UsersID']=$result[0];
$_SESSION['U_YearID']=$result[1];
if($_SESSION['U_YearID']==1){
header("Location:login_success.php");
exit;
}
if($_SESSION['U_YearID']==2){
header("Location:login_success2.php");
exit;
}
if($_SESSION['U_YearID']==4){
header("Location:login_success4.php");
exit;
}
} else {
echo "Wrong Username or Password";
}
?>