$sql = "INSERT INTO `tblpages` ";
$sql .= "(`page_name`, `page_content`, `page_date`)";
$sql .= "VALUES";
$sql .= "('";
$sql .= htmlspecialchars( stripslashes( $HTTP_POST_VARS['pagename'] ) );
$sql .= "', '";
$sql .= $HTTP_POST_VARS['EditorDefault'];
$sql .= "', '";
$sql .= $tday;
$sql .= "')";
$result = mysql_query($sql,$connection) or die ("Could not connect to database");
Looks ok when you break it up and remove the "s and extra ()s.