Warning When Using Superglobal Variables

Hackers often use these to try and inject code etc.  When accessing superglobal variables ensure you sanitise them.  E.g.

  $CameFromPage = htmlentities($_SERVER['HTTP_REFERER']);    //htmlentities() converts things like < > " \ etc into HTML strings like &lt; so they become harmless.

Superglobal Variables

Always available in all scopes


References all variables available in global scope


Server and execution environment information


HTTP GET variables


HTTP POST variables


HTTP File Upload variables


HTTP Request variables


Session variables


Environment variables


HTTP Cookies


The previous error message


Raw POST data


HTTP response headers


The number of arguments passed to script


Array of arguments passed to script

Full descriptions

