As duff suggests, you should read perlsec.
Just to stress the point: accepting input from an untrusted source - especially when that input will be eval'ed by perl - can be a serious security hole.

Imagine if the input was `rm -rf /`...

