Im modifying my work's website and I need some advice. I'm trying to figure out how I can avoid injection attacks, while still accepting valid input.

An example is: if a user types an apostrophe...