stringname.replace("'","''")

Or just use parameterized queries/stored procs.