Просмотр файла news/includes/admin.valid.php
<?php $login = mysql_escape_string($_COOKIE['login']); $pass = mysql_escape_string($_COOKIE['pass']); $sql = mysql_query("SELECT * FROM `".$db_pref."admin` WHERE `login` = '$login' && `pass` = '$pass'"); $_USER = mysql_fetch_assoc($sql); ?>