In your preferences:
$name = mysql_real_escape_string(strip_tags($_POST['name'])); OR
$name = mysql_real_escape_string(htmlentities($_POST['name'])); OR
$name = mysql_real_escape_string(htmlspecialchars($_POST['name'])); OR
$name = str_replace(array("<", ">"), array("",""), $_POST['name']); $name = mysql_real_escape_string($name);
I don't tend to use str_replace so I may have given a bad example!