Да.Лучше использовать параметризованный режим запросов Mysqli.
<?php
if (isset($_POST['user']) && isset ($_POST['pass'])) {
$user = mysql_real_escape_string ($_POST['user']),
$pass = mysql_real_escape_string ($_POST['pass']);
$conn = new mysqli("$db_host", "$db_user", "$db_pass", "$db");
$sql = "select * from admin where username=? and password=?";
$cmd = $conn->prepare($sql);
$cmd->bind_param("ss", $user, $pass);
$cmd->execute();
......
......
else {
echo "Username and password cant not be null !";
}
?>