function escapeParam( sParam ) {
	sParam.replace( /[\"\'][\s]*javascript:(.*)[\"\']/gi, "\"\"" );
	sParam = sParam.replace( /script(.*)/gi, "" );    
	sParam = sParam.replace( /eval\((.*)\)/gi, "" );
	sParam = sParam.replace( /alert\((.*)\)/gi, "" );
	sParam = escape( sParam );
	return( sParam );
}
