Superglobals are built-in arrays available in every scope without
global.
| Variable | Contains |
|---|---|
$_GET |
Query-string parameters (?id=5) |
$_POST |
Form fields submitted via POST |
$_REQUEST |
GET + POST + cookies (avoid — ambiguous) |
$_SERVER |
Request and server info |
$_SESSION |
Per-visitor session data |
$_COOKIE |
Cookies sent by the browser |
$_FILES |
Uploaded files |
$_ENV |
Environment variables |
$GLOBALS |
All global variables |
$_GET
PHP
<?php
// URL: product.php?id=42&sort=price
$id = $_GET['id'] ?? null;
$sort = $_GET['sort'] ?? 'name';$_POST
PHP
<?php
$email = $_POST['email'] ?? '';$_SERVER
PHP
<?php
echo $_SERVER['REQUEST_METHOD']; // GET or POST
echo $_SERVER['PHP_SELF']; // current script path
echo $_SERVER['HTTP_HOST']; // scolarnepal.com
echo $_SERVER['REMOTE_ADDR']; // visitor IP
echo $_SERVER['REQUEST_URI']; // /product.php?id=42Treat every superglobal as untrusted
Everything in $_GET, $_POST, $_COOKIE and most of $_SERVER comes
from the visitor and can be anything at all. Two rules:
- Escape on output with
htmlspecialchars()to prevent XSS. - Never concatenate into SQL — use prepared statements.
PHP
<?php
// WRONG — the visitor controls what lands in your HTML
echo "Hello " . $_GET['name'];
// RIGHT
echo "Hello " . htmlspecialchars($_GET['name'] ?? '', ENT_QUOTES, 'UTF-8');Even $_SERVER['PHP_SELF'] is attacker-controllable in some setups —
escape it before echoing it into a form action.