Sorry, but how is PHP at fault? You can shoot yourself in the foot with ANY programming language.
Think of it as the difference between the language keeping loaded footguns under its pillow with the safety off and keeping unloaded footguns in a locked gun safe. One is a lot less likely to get used than the other, even if either one will shoot your foot just as well.
Last week I had to rewrite an import script to use mysql_query(), with mysql_real_escape_string() and quotes for every query variable.