Asp.Net Login & Session

string usname, password;
usname=username.Text;
password=pass.Text;

string query = "select * from signup where uname='"+usname+"' and password='"+password+"'";
cmd = new SqlCommand(query, con);
cmd.ExecuteNonQuery();
SqlDataAdapter adt = new SqlDataAdapter(cmd);
DataSet ds = new DataSet();
DataTable dt = new DataTable();
adt.Fill(ds);
dt = ds.Tables[0];
if (dt.Rows.Count > 0)
{
    string user_id;
    string user_name;
    user_id = dt.Rows[0]["u_id"].ToString();
    user_name = dt.Rows[0]["uname"].ToString();
    Session["uid"] = user_id.ToString();
    Session["username"] = user_name.ToString();
    Response.Redirect("home.aspx");
}
else
{
    msg.Text = "Wrong Username or Password";
}

Comments