PHP Superglobals

Superglobals are built-in arrays available in every scope without global.

Variable Contains
$_GET Query-string parameters (?id=5)
$_POST Form fields submitted via POST
$_REQUEST GET + POST + cookies (avoid — ambiguous)
$_SERVER Request and server info
$_SESSION Per-visitor session data
$_COOKIE Cookies sent by the browser
$_FILES Uploaded files
$_ENV Environment variables
$GLOBALS All global variables

$_GET

PHP
<?php
// URL: product.php?id=42&sort=price
  $id   = $_GET['id']   ?? null;
  $sort = $_GET['sort'] ?? 'name';

$_POST

PHP
<?php
  $email = $_POST['email'] ?? '';

$_SERVER

PHP
<?php
  echo $_SERVER['REQUEST_METHOD'];  // GET or POST
  echo $_SERVER['PHP_SELF'];        // current script path
  echo $_SERVER['HTTP_HOST'];       // scolarnepal.com
  echo $_SERVER['REMOTE_ADDR'];     // visitor IP
  echo $_SERVER['REQUEST_URI'];     // /product.php?id=42

Treat every superglobal as untrusted

Everything in $_GET, $_POST, $_COOKIE and most of $_SERVER comes from the visitor and can be anything at all. Two rules:

  1. Escape on output with htmlspecialchars() to prevent XSS.
  2. Never concatenate into SQL — use prepared statements.
PHP
<?php
  // WRONG — the visitor controls what lands in your HTML
  echo "Hello " . $_GET['name'];

  // RIGHT
  echo "Hello " . htmlspecialchars($_GET['name'] ?? '', ENT_QUOTES, 'UTF-8');

Even $_SERVER['PHP_SELF'] is attacker-controllable in some setups — escape it before echoing it into a form action.