Is my Login Script is vulnerable to SQL Injection?

Viewed 318

2 days ago, a hacker got into a Admin Account. He told us that login.php is vulnerable.

But I can't find out how as I escaped the inputs:

$salt      = '78sdjs86d2h';
$username = mysqli_real_escape_string($DB_H, addslashes($_POST['username']));
$password = mysqli_real_escape_string($DB_H, addslashes($_POST['password']));
$hash1 = hash('sha256', $password . $salt);
$hash = strtoupper($hash1);

$check = mysqli_query($DB_H, "SELECT * FROM players WHERE Name='$username' && Password = '$hash'");

if(mysqli_num_rows($check) != 0)
4 Answers
Related