Changed db_escape function to avoid XSS atacksvia db javascript injection