How can the code be improved to prevent SQL injection vulnerabilities?
SQL injection vulnerabilities can be prevented by using prepared statements with parameterized queries. This approach ensures that user input is treated as data rather than executable SQL code, effectively preventing malicious SQL injection attacks.
// Establish a database connection
$pdo = new PDO('mysql:host=localhost;dbname=my_database', 'username', 'password');
// Prepare a SQL statement with placeholders
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = :username");
// Bind parameters to placeholders
$stmt->bindParam(':username', $_POST['username']);
// Execute the prepared statement
$stmt->execute();
// Fetch the results
$results = $stmt->fetchAll();
Related Questions
- What is the best practice for resizing and resampling images in PHP, specifically when dealing with thumbnails?
- How can dependency injection be implemented to improve the handling of database connections in PHP applications?
- How can one address the issue of using different stylesheets for different pages in PHP?