What potential errors or issues can arise when displaying user data in PHP from a database?
One potential issue when displaying user data in PHP from a database is SQL injection attacks, where malicious code is inserted into SQL statements. To prevent this, always use prepared statements with parameterized queries to sanitize user input before executing SQL queries.
// Connect to the database
$pdo = new PDO('mysql:host=localhost;dbname=database', 'username', 'password');
// Prepare a statement with a parameterized query
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username');
// Bind the user input to the parameter
$stmt->bindParam(':username', $_GET['username']);
// Execute the query
$stmt->execute();
// Fetch the results
$user = $stmt->fetch();
// Display user data
echo 'Username: ' . htmlspecialchars($user['username']);
echo 'Email: ' . htmlspecialchars($user['email']);