How can PHP developers prevent SQL injection attacks when handling user input in forms?
To prevent SQL injection attacks when handling user input in forms, PHP developers should use prepared statements with parameterized queries. This approach separates the SQL query logic from the user input data, preventing malicious SQL code from being executed.
// Establish a database connection
$pdo = new PDO("mysql:host=localhost;dbname=mydatabase", "username", "password");
// Prepare a SQL statement with a placeholder for user input
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = :username");
// Bind the user input to the parameter in the prepared statement
$stmt->bindParam(':username', $_POST['username']);
// Execute the query
$stmt->execute();
// Fetch the results
$results = $stmt->fetchAll();