This should be just about what you need, it's nothing great just made it real quick.
You'll have to edit it a bit to fit your database (table names etc) but should work.
Code:
<?php
$mysql_hostname = "localhost";
$mysql_user = "USERNAME";
$mysql_password = "PASSWORD";
$mysql_database = "DATABASE";
?>
<?php
if (isset($_POST['uid']) && isset($_POST['gold'])) {
$user = $_POST['uid'];
$gold = $_POST['gold'];
$mysql_con = mysql_connect($mysql_hostname, $mysql_user, $mysql_password)
or die("Unable to connect to database.");
mysql_select_db($mysql_database, $mysql_con) or die("Unable to select database.");
$sql = "UPDATE characters SET Gold = 0 WHERE UID = '$uid'";
if (!mysql_query($sql))
die('Error: ' . mysql_error());
echo "Updated!";
}
else if (isset($_POST['user']) && isset($_POST['pass'])) {
$user = $_POST['user'];
$pass = $_POST['pass'];
$mysql_con = mysql_connect($mysql_hostname, $mysql_user, $mysql_password)
or die("Unable to connect to database.");
mysql_select_db($mysql_database, $mysql_con) or die("Unable to select database.");
$sql = "SELECT UID FROM accounts WHERE Account = '$user' AND Password_Plain = '$pass'";
$uid = mysql_result(mysql_query($sql), 0) or die("Invalid Username or password.");
$sql2 = "SELECT Gold FROM characters WHERE UID = $uid";
$result = mysql_query($sql2) or die("Invalid UID.");
if ($row = mysql_fetch_array($result)) {
$gold = $row['Gold'];
echo "Money: $gold<br />";
if ($gold >= 999999) {
echo "<form method='post'>";
echo "<input type='hidden' value=$uid name='uid' />";
echo "<input type='hidden' value=$gold name='gold' />";
echo "<input type='submit' value='Reset to 0' />";
echo "</form>";
}
}
}
?>
<form method="post">
<table>
<tr>
<td>Username:</td>
<td><input type='text' name='user' /></td>
</tr>
<tr>
<td>Password:</td>
<td><input type='password' name='pass' /></td>
</tr>
<tr>
<td></td>
<td><input type='submit' value="Find" /></td>
</tr>
</table>
<form>