Une possibilité :

$sql="SELECT * FROM acces WHERE admin='" . mysql_real_escape_string($_POST[admin]) . "' AND pass = '" . mysql_real_escape_string($_POST[motdepasse]) . "'" ;...