We did a scan on our web page for vulnerabilities. We received a critical Blind SQL injection in the following query. I am using the prepared statements. What else I can do to prevent SQL Injection attack? Please let me know. Here is my example code. I appreciate any suggestions.
$first_name = $_POST["first-name"];
$middle_name = $_POST["middle-name"];
$last_name = $_POST["last-name"];
$qry = $pdo_conn->prepare('INSERT INTO table1(first_name, last_name, middle_initial) VALUES (?, ?, ?)');
$qry->execute(array($first_name, $last_name, $middle_name));