Just wanna add: NEVER TRUST YOUR USER

http://www.php.net/addslashes

http://www.php.net/strip_tags