I need help with checking password all other works good
<form class="form-horizontal" action="" method="post" id="form1" style="width: 95%; margin: 0 2.5%" novalidate>
<div class="control-group">
<label class="control-label" for="ea">Email Address:</label>
<div class="controls">
<DIV align="left"><input type="email" name="email" id="email" class="input-large valid"></div>
</div>
</div>
<div class="control-group">
<label class="control-label" for="pa">Password:</label>
<div class="controls">
<DIV align="left"><input type="password" name="password" id="password" class="input-large valid"></div>
</div>
</div>
<div class="control-group">
<div class="controls" id="exist_wait"></div>
</div>
<div class="control-group">
<label class="control-label"></label>
<div class="controls">
<tr valign="baseline">
<td nowrap align="right"> </td>
<td> <DIV align="left"><input type="submit" name="Submit1" class="submit" value="Submit"></div></td>
</tr>
</form>
if(isset($_SESSION['user'])!="")
{
}
$conn= mysqli_connect("localhost","root","");
if(mysqli_connect_error()) {
die('Could not connect: ' . mysqli_connect_error());
}
$conn->select_db('cars123');
if(isset($_POST['Submit1']))
{
$email = mysqli_real_escape_string($conn, $_POST['email']);
$upass = mysqli_real_escape_string($conn, $_POST['pass']);
$res=mysqli_query($conn, "SELECT * FROM users WHERE email='$email' ") or die("Error: ".mysqli_error($dbc));
$row=mysqli_fetch_array($res, MYSQLI_ASSOC);
if($row['password']==md5($upass))
{
$_SESSION['user'] = $row['user_id'];
$_SESSION['password']= $row['password'];
echo'<script>window.location="http://localhost/carbooking3/16%20y/korak1.php";</script>';
}
else
{
echo'<script>window.location="http://localhost/carbooking3/16%20y/korak3.php";</script>';
}
}
CREATE TABLE `users` (
`user_id` int(5) NOT NULL,
`email` varchar(255) NOT NULL,
`username` varchar(25) NOT NULL,
`password` varchar(255) NOT NULL
) ENGINE=InnoDB DEFAULT CHARSET=latin1;