Just to warn, you need to be aware that MySQL Injections is likely possible if you doing something out of phpVMS.
Do some research on that and you'll see a few things to prevent MySQL injections out of a external login form.
For the passwords, phpVMS uses md5, but there's salt inside the md5.
Example...
$hash = md5($password . $userinfo->salt);
if ($hash == $userinfo->password) {
//okay, password is good
return true;
} else {
//nope, password is wrong...
return false;
}