Just to warn, you need to be aware that MySQL Injections is likely possible if you doing something out of phpVMS. 
Do some research on that and you'll see a few things to prevent MySQL injections out of a external login form. 
For the passwords, phpVMS uses md5, but there's salt inside the md5. 
Example... 
 
$hash = md5($password . $userinfo->salt);
if ($hash == $userinfo->password) {
		//okay, password is good
		return true;
} else {
		//nope, password is wrong...
		return false;
}