Before I start, I will state that at the moment I'm stuck with the old mysql API.
I use this function for password creation.
$password = $_POST[password];
$passwordhashed = password_hash($password, PASSWORD_DEFAULT);
$query_f = mysql_query("SELECT fiscal FROM list WHERE password='$password'");
You don't. Look up the user by some identifier (like a username or email address) and then check if the password field matches with
password_verify. You specifically can't lookup a user by salted password hash, that would defeat the point of salting.