You would navigate to your myalbum module folder and place your new images over the corresponding old images....
all of the modules images should be contained within the module folder.
Anytime you allow someone to upload to your server you are creating a hole in your security
i mean its as easy as
virus.php -> imnotaviruspleasedontpayattentiontome.jpg
Your best bet would be to provide your users with a pathto field, and let imageshack worry about it.