String.prototype.escapeHTML = function () {
return(
this.replace(/&/g,'&').
replace(/>/g,'>').
replace(/</g,'<').
replace(/"/g,'"')
);
};
// example
document.getElementById('some_div').innerHTML =
document.getElementById('some_textarea').value.escapeHTML()