<?
session_start();
$user=$_POST["user"];
$pass=$_POST["pass"];
include ‘konek.php’;
$cekadm=mysql_query(“select * from admin where admin=’$user’ and pass=’$pass’”);
$cekmemb=mysql_query(“select * from member where member=’$user’ and pass=’$pass’”);
if ((mysql_num_rows($cekadm))==1){
session_register(‘user’);
header(“location:admin.php”);
}
elseif((mysql_num_rows($cekmemb))==1){
session_register(‘user’);
header(“location:member.php”);
}
else{
header(“location:gagallogin.php”);
}
?>


“$cekadm=mysql_query(”select * from admin where admin=’$user’ and pass=’$pass’”);”
Sebaiknya kalo mengecek user lebih baik menggunakan sintaks sbb:
if(strcmp($password, $row["password"]))
{
doSuccess();
}
else
{
echo(‘Password doest not valid! Please try again!’);
}
Soalnya kalo langsung username dan password diquery langsung memungkinkan nantinya terjadi SQL Injection.
Semoga membantu