How can SQL Injection vulnerabilities be addressed in PHP code, especially when dealing with user input?

SQL Injection vulnerabilities can be addressed in PHP code by using prepared statements with parameterized queries. This approach ensures that user input is treated as data rather than executable SQL code, preventing malicious SQL injection attacks.

// Establish a connection to the database
$pdo = new PDO('mysql:host=localhost;dbname=database', 'username', 'password');

// Prepare a SQL statement with a parameterized query
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username');

// Bind the user input to the parameter
$stmt->bindParam(':username', $_POST['username']);

// Execute the query
$stmt->execute();

// Fetch the results
$results = $stmt->fetchAll(PDO::FETCH_ASSOC);

// Loop through the results and do something with them
foreach ($results as $row) {
    // Do something with the data
}