// pid of product being reviewed must be included on the review form
// clean review form data
$pid = preg_replace("/[^0-9]/", "", $_REQUEST["pid"]);
$name = preg_replace("/[^0-9a-z. -]/i", "", $_REQUEST["name"]);
$comments = preg_replace("/[^0-9a-z.?! -]/i", "", $_REQUEST["comments"]);
$rating = preg_replace("/[^0-9]/", "", $_REQUEST["rating"]);
// store review for pid
// assumed pid, rating are integer, name, comment are varchar.
$connhandle = mysqli_connect(...your database...);
$sql = "insert into reviews (pid, name, comment, rating) values ($pid, '$name', '$comments', $rating)";
$r = mysqli_query($connhandle, $sql);