Simmo, was that image script custom? I only ask because I had a custom image loader on my site as well. Not sure if that was the exploit or how, even, I could find out what the exploit was.
I only assumed it was some sort of forms exploit.
It was a bastardised version of a standard script. I ripped out the routines and modified them so it could well have been something I did.