How can the PHP script be improved to handle SQL injection vulnerabilities?

To improve the PHP script to handle SQL injection vulnerabilities, you should use prepared statements with parameterized queries instead of directly inserting user input into SQL queries. This approach helps to prevent malicious SQL injection attacks by separating the SQL logic from the user input data.

// Establish a database connection
$pdo = new PDO("mysql:host=localhost;dbname=mydatabase", "username", "password");

// Prepare a SQL statement with a parameterized query
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = :username");

// Bind the parameter value to the query
$stmt->bindParam(':username', $_POST['username']);

// Execute the statement
$stmt->execute();

// Fetch the results
$results = $stmt->fetchAll(PDO::FETCH_ASSOC);

// Loop through the results
foreach ($results as $row) {
    echo $row['username'] . "<br>";
}