include "db.php";
extract($_POST);
$fname = str_replace("'","`",$fname);
$fname = mysql_real_escape_string($fname); <----
$lname = str_replace("'","`",$lname);
$lname = mysql_real_escape_string($lname);
Is about a registration form for a forum