Unless there's something I'm missing...
Insert
sql=sql & "'" & Replace(Request.QueryString("strength"),"'","'") & "',"
sql=sql & "'" & Replace(Request.QueryString("improve"),"'","'") & "',"
sql=sql & "'" & Replace(Request.QueryString("other"),"'","'") & "')"
Update
sql=sql & "Strength='" & Replace(Request.QueryString("strength"),"'","'") & "',"
sql=sql & "Improve='" & Replace(Request.QueryString("improve"),"'","'") & "',"
sql=sql & "Comments='" & Replace(Request.QueryString("other"),"'","'") & "' "