1// This should REALLY be validated too
2String custname = request.getParameter("customerName");
3// Perform input validation to detect attacks
4String query = "SELECT account_balance FROM user_data WHERE user_name = ? ";
5PreparedStatement pstmt = connection.prepareStatement( query );
6pstmt.setString( 1, custname);
7ResultSet results = pstmt.executeQuery( );
8
1
2// use prepared statement to prevent SQL injection
3$preparedStatement = $dbConnection->prepare('SELECT * FROM animals WHERE name = ?');
4$preparedStatement->bind_param('s', $name);
5$preparedStatement->execute();
6$result = $preparedStatement->get_result();
7while ($row = $result->fetch_assoc()) {
8// Process $row
9}
10