$sql = "insert into table (id, name,lastname) values('$id','".$_POST['name']."','".$_POST['lastname']."')"; $query = mysql_query($sql);
$name = htmlspecialchars(strip_tags($_POST['name']));