If you use jQuery’s .html
method it parses out the script tag and evals it:
$("div").html('<script type="text/javascript">alert("This should work")</script>');
If jQuery isn’t an option you could write this yourself using either (1) a regular expression, or (2) parse out the DOM tree and find script tags. (#2 is how jQuery does it)