Changed db_escape function to avoid XSS attacks via js db injection