mysql_real_escape_string() ile gelen verileri escape et, sql injectiona karşı.

http://www.php.net/manual/tr/functio...ape-string.php