PHP/HTML/html entity decode
string html_entity_decode ( string html [, int options [, string charset]] ) converts an &-escaped string into its original format
<?
$f = "Bill & Ben";
$s = htmlentities($f);
$unsafe = html_entity_decode($s);
?>