<?php
include("db.php");
$dbh=mysql_connect ($host,$account,$acc_pw) or die (mysql_error());
mysql_select_db ($table);
$user=$_SESSION['login'];
$rs=mysql_query($sql, $dbh);
$row=mysql_fetch_array($rs);
$user_name = ucfirst(strtolower($row['Username']));
$pw=strtolower($row['Password']);
extract($_POST);
$pass_old=md5($pass_old);
############
#echo "PASS_OLD: $pass_old";
#echo "<br/>PW: $pw";
#echo "<br/>PASS1: $pass_new1";
#echo "<br/>PASS2: $pass_new2";
##############################
if ($pass_old==$pw)
{
if ($pass_new1==$pass_new2)
{
$pass_new1=md5($pass_new1);
$sql="UPDATE Accounts SET Password='$pass_new1' WHERE Username='$user'";
$rs=mysql_query($sql,$dbh);
if ($rs)
echo "<b>Password updated successfully!</b>";
echo "\n\n<br/><br/>\n\n";
echo "<a href='?id=profile'>Back to $user_name's Profile</a>";
}
else
{
echo "<span id='error'>Error!</span>";
echo "\n<br/><br/>";
echo "Your <b>new passwords</b> do not match.";
echo "Please go <a href='?id=change_password'>back</a>";
echo "\nand supply the correct <b>new passwords</b> to change your password successfully.";
}
}
else
{
echo "<span id='error'>Error!</span>";
echo "\n<br/><br/>";
echo "Your old password is not correct.";
echo "<br/><br/>\n";
echo "Please go <a href='?id=edit_profile'>back</a>";
echo "\nand supply the correct password to change your password successfully.";
}
mysql_close($dbh);
?>