Citation :
Script Location
Perhaps oddly, the $_SERVER values associated with the current page, including PHP_SELF, PATH_
INFO, and PATH_TRANSLATED, are not entirely reliable, either. On Apache for example, these values
can be appended with URL-encoded JavaScript or HTML entities that if displayed directly,
cause the browser to execute the specified code.