$_SERVER holds the server's CGI-style variables plus each request header as HTTP_NAME. Here server.php is just print_r($_SERVER);, called with extra path info and a forged header (trimmed):
$ curl -s -H 'X-Forwarded-For: 203.0.113.9' "$U/server.php/extra?sort=title"
...
[REMOTE_ADDR] => 127.0.0.1
...
[SCRIPT_NAME] => /server.php
[PATH_INFO] => /extra
[PHP_SELF] => /server.php/extra
...
[HTTP_X_FORWARDED_FOR] => 203.0.113.9
...REMOTE_ADDR (the TCP peer), SCRIPT_NAME, SCRIPT_FILENAME and REQUEST_TIME_FLOAT are the server's. The method, the URI, PATH_INFO and every HTTP_* key are the client's, which typed 203.0.113.9 itself. Behind a proxy, let mod_remoteip rewrite REMOTE_ADDR from trusted proxies only (ProxyPass). PHP_SELF carries the client's PATH_INFO, so echoing it into a form action is an XSS hole; use SCRIPT_NAME. HTTPS is non-empty only on TLS requests.