How can SQL injection vulnerabilities be addressed in PHP code when interacting with a MySQL database?

SQL injection vulnerabilities in PHP code when interacting with a MySQL database can be addressed by using prepared statements with parameterized queries. This approach ensures that user input is treated as data rather than executable SQL code, preventing malicious SQL injection attacks.

// Establish a connection to the MySQL database
$pdo = new PDO('mysql:host=localhost;dbname=mydatabase', 'username', 'password');

// Prepare a SQL statement with a parameterized query
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username');

// Bind the user input to the parameter
$stmt->bindParam(':username', $_POST['username']);

// Execute the prepared statement
$stmt->execute();

// Fetch the results
$results = $stmt->fetchAll(PDO::FETCH_ASSOC);

// Use the results as needed
foreach ($results as $row) {
    echo $row['username'] . '<br>';
}