<?php
if (count($_POST) > 0) {
mysql_connect('a', 'b', 'c');
$escaped = array();
foreach ($_POST['selectbundesland'] as $bl) {
$escaped[] = mysql_real_escape_string($bl);
}
$q = "
SELECT
`col1`, `col2`
FROM
`table`
WHERE
`col3` IN ('". implode("', '", $escaped) ."')
";
var_dump($q);
}
?><!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>New</title>
</head>
<body>
<form method="post" action="">
<select multiple size="5" name="selectbundesland[]">
<option value="Schleswig-Holstein">Schleswig-Holstein</option>
<option value="Bayern">Bayern</option>
<option value="Mecklenburg-Vorpommern">Mecklenburg-Vorpommern</option>
<option value="Thüringen">Thüringen</option>
<option value="Hamburg">Hamburg</option>
<option value="Berlin">Berlin</option>
<option value="Baden-Württemberg">Baden-Württemberg</option>
<option value="Saarland">Saarland</option>
<option value="Rheinland-Pfalz">Rheinland-Pfalz</option>
<option value="Hessen">Hessen</option>
<option value="Nordrhein-Westfalen">Nordrhein-Westfalen</option>
<option value="Thüringen">Thüringen</option>
<option value="Sachsen">Sachsen</option>
<option value="Bremen">Bremen</option>
<option value="Niedersachsen">Niedersachsen</option>
<option value="Brandenburg">Brandenburg</option>
</select>
<input type="submit" name="button1" value="Absenden">
</form>
</body>
</html>