The PHP world is so adorable. It's like a bunch of little puppies, running into each other and falling over and tumbling around.
$resulset->search({ column1 => some_sub($arg), column2 => $value2, ...});
Many subs may behave in unexpected ways when using list context, such as returning an empty list. You may end up with values, which are normally escaped, becoming keys in the hashref. DBIC only does the simplest of checks on the key values, leaving your code open to an SQL injection.
This sort of issue is unfortunately prevalent. It is not just limited to PHP and dismissing it as such does everyone a disservice.
I am interested in removing all and any attack vectors, but I can't fix problems without knowing about them. So please do get back to me on this.
Cheers