How can the use of $_POST and $_GET variables affect the execution of PHP queries in a script?

Using $_POST and $_GET variables directly in PHP queries can make your code vulnerable to SQL injection attacks. To prevent this, you should always sanitize and validate user input before using it in a query. One way to do this is by using prepared statements with parameterized queries, which separate the SQL query from the user input.

// Example of using prepared statements to prevent SQL injection

// Establish a database connection
$pdo = new PDO('mysql:host=localhost;dbname=mydatabase', 'username', 'password');

// Prepare a SQL query with a placeholder for the user input
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username');

// Bind the sanitized user input to the placeholder
$stmt->bindParam(':username', $_POST['username']);

// Execute the query
$stmt->execute();

// Fetch the results
$results = $stmt->fetchAll();

// Loop through the results
foreach ($results as $row) {
    // Output the data
    echo $row['username'] . '<br>';
}