What is wrong with this code?
Code:
<?php
$con = mysql_connect("mysql157.secureserver.net","132591","lotrt2t");
mysql_select_db("132591",$con);
$sql = "CREATE TABLE users(
user varchar(12),
password varchar(12)
)";
mysql_query($sql, $con);
$sql = "SELECT * FROM users WHERE user = '$_POST[username]'";
$result = mysql_query($sql, $con);
echo "query: \"$sql\"<br>";
echo ( $result ) ? "<br>found one!<br>" : "<br> didn't find one! <br>" ;
echo "confirm: \"" . $_POST['confirm'] . "\"";
echo "password: \"" . $_POST['password'] . "\"";
if( $_POST['confirm'] == $_POST['password']){
if(!$result){
$sql = "INSERT INTO users (user, password) VALUES('$_POST[username]','$_POST[password]')";
echo "query: \"$sql\"";
mysql_query($sql, $con);
}
else{
echo "Username already exists. Sorry!";
}
}
else{
echo "You are not logged on.";
}
?>