And you're complaining about crappy browser security and you're then supporting IE6? Why support such an outdated browser when you
know it has numerous well documented and unpatched vulnerabilities?
Yes, yes, I know, the powers that be need this support for some explainable support even though worldwide IE6 usage is <1% etc etc. Whatever, it's just not worth the hassle. Show them a message and tell them to upgrade or use an alternate browser. I refuse to take any work on (I was freelance until recently) which requires IE6 support, and is a specific question I ask at interview time.