elseif ($_SESSION["username"] == $_GET["changeinfo"]) {
$sql = mysql_query("SELECT * FROM userinfo WHERE username='" . $_SESSION["username"] . "'");
while($row = mysql_fetch_array($sql)) {
echo '<form method="POST" action="members.php?uname&changeinfo="' . $_SESSION["username"] . '">';
echo '<input type="text" name="name" value="' . $row["firstname"] . '">';
echo '<input type="submit" value="Change">';
echo '</form>';
$firstname = $_POST["name"];
mysql_query("UPDATE userinfo SET firstname='$firstname' WHERE username='" . $_SESSION["username"] . "'");
}
}