xixi/trunk: added prepared sql statements to esql db queries. they should escape the content but a insert of xml code with ticks still fails ;(