This is how I do it:
Old:
strSql = "Insert Into Individual (Name, FirstName) Values ('" & strINDIName & "', '" & strINDIFirstName & "')"[/Code]
Change to:
[Code]
strSql = "Insert Into Individual (Name, FirstName) Values ('" & strINDIName.Replace("'", "''") & "', '" & strINDIFirstName.Replace("'", "''") & "')"[/Code]
Or to clean it up:
[Code]
strSql = String.Format("Insert Into Individual (Name, FirstName) Values ('{0}', '{1}')", _
strINDIName.Replace("'", "''"), _
strINDIFirstName.Replace("'", "''"))[/Code]