Courseiva
Client-Side Attacks →hardMultiple Choice

PEN-200 Client-Side Attacks Practice Question

You are assessing a web application that reflects user input into an HTML attribute value without quotes, such as `<input value=USER_INPUT>`. Which payload is most likely to execute JavaScript in the victim’s browser?

⚠ Common exam trap

The trap here is applying a quoted-attribute or HTML-body payload to an unquoted attribute context, where whitespace rather than quotes determines attribute boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`onmouseover=alert(document.domain)`

In an unquoted HTML attribute, attribute boundaries are defined by whitespace. Injecting a space followed by a new event handler attribute, such as onmouseover=alert(document.domain), adds executable JavaScript to the element. When the corresponding event fires, the code runs. Payloads that rely on quotes or script tags fail because the parser is already inside an attribute value and does not interpret them as structure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    `onmouseover=alert(document.domain)`

    Why this is correct

    In an unquoted attribute context, whitespace separates attributes. Injecting onmouseover=alert(document.domain) creates a new event handler attribute on the input element. When the user moves the mouse over the input, the JavaScript executes. No quote is needed because the attribute value is unquoted, and the payload uses a space to break out of the value and start a new attribute.

  • ✗

    `' onmouseover='alert(document.domain)`

    Why it's wrong here

    This payload assumes a single-quoted attribute context. Since the attribute is unquoted, the single quote is treated as part of the value, and the onmouseover text is not parsed as a new attribute. The browser looks for whitespace to end the unquoted value. Without a space before onmouseover, the payload does not create an event handler and fails.

  • ✗

    `javascript:alert(document.domain)`

    Why it's wrong here

    The javascript: pseudo-protocol is only useful in a URL context, such as an href or src attribute. Here the injection point is a value attribute of an input element, not a navigable URL. The string is stored as the input’s value and is never executed as code. This payload does not break out of the attribute or create an event handler.

  • ✗

    `"><script>alert(document.domain)</script>`

    Why it's wrong here

    The reflection is inside an unquoted attribute value, not in a quoted attribute or HTML body. The double quote and closing angle bracket do not break out because there is no opening quote to close, and the script tag is inside the attribute value. The browser treats the entire string as part of the value attribute, so no script element is created.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.