In PHP, Remote file inclusion can be conducted via input from $_GET
, $_POST
, $_COOKIE
. I know it is improbable, but is it possible (by any chance) to fake the value come out of $_SERVER
?
I mean, can $_SERVER
become the source of Remote file inclusion even on rare occasion?