As far as ldap injections go, you can manually escape the dangerous characters for ldap, which are not that many for your exact search filter:
* ( ) & "