How does mysql_real_escape_string prevent SQL Injections?
http://www.php.net/mysql_real_escape_string