added code to avoid sql-injection