In your email.php, find:
PHP Code:
'" . mysql_real_escape_string($_POST['from']) . "',
'" . mysql_real_escape_string($_POST['subject']) . "',
'" . mysql_real_escape_string($_POST['message']) . "')
And replace with:
PHP Code:
'" . addslashes(mysql_real_escape_string($_POST['from'])) . "',
'" . addslashes(mysql_real_escape_string($_POST['subject'])) . "',
'" . addslashes(mysql_real_escape_string($_POST['message'])) . "')
Not tested.