Is there any reason why a check on the extension wouldn't solve the problem?
$fileDetails = pathinfo($src);
$ext = strtolower($fileDetails['extension']); $fileDetails = pathinfo($src);
$ext = strtolower($fileDetails['extension']);Even if you don't have such vulnerabilities you probably don't want people to be able to upload images to your server. They could easily send you over quota on shared hosting and use your bandwidth for serving their own images (including child porn).
This still allows the attacker to host images on your site though.
Well put.
Probably best to remove allowed hosts altogether.