Call addslashes() within your sql query on the variable for every field in which a user might enter a single quote.
eg:
$sql = "INSERT INTO your_table (one, two, three) VALUES ('" . addslashes($one) . "', '". addslashes($two) . "', '" . addslashes($three) . "')";
geoff