For instance, I used PHP about 5 years ago for my first paid programming project, and have not touched it since. It's equally untrue for me to leave PHP off my resume (implying I have no experience) and to put it on unqualified (implying I have recent experience). I simply rate myself low (I think I'm a 3/10) and explain what that means if anyone asks. That way I can list everything I've worked with and would consider using again while bypassing any mismatched expectations early on in the process.
I've heard of some "standard" rating schemes, particularly one that Google uses, but I don't recall them off the top of my head.
"Years of experience" isn't a great indicator either. The language I'm most proficient in today is the one I learned most recently.
To your under/overrating problem, I think that's where ?'s have to come into play. Someone who ranks themselves very highly needs to be able to back it up, and it's your responsibility as an interviewer to get appropriate people to do that vetting if you can't. Someone who rates themselves as a 10 with Solaris, for example, needs to be vetted by the best damned sysadmin you can get. Someone who rates themselves as a 3-4 can probably be comfortably vetted by an experienced engineer.
I try to knock myself down roughly a point off where I think I ought to be, and I've found that works well in interviews. For instance, at my second job interview (after only a six month internship), I was asked "on a scale of 1-10, how do you rate yourself as a software engineer?" I replied that I rated myself a 2-3, but I considered 10 to be an engineer with a world-class reputation like Steve McConnell or Steve Yegge. Compared to the people with my experience, I rated myself an 8, but I recognized that I had a long way to go.
Humility works well if you make it sound rational and not just like kow-towing.
Likewise, you could omit languages that you know well but don't want to use in your job.
I'm the kind of person who picks up languages for fun, so I learn a new language pretty fast. So, I'm usually willing to say I have "experience" in a language I've dabbled in (and done a couple projects solely for the purpose of learning the language); if I need the language for the job, I know I'll be able to handle it just fine thanks to Google.
A CV with a million niche languages on it looks ridiculous, however, so I try to tailor the list to what I think would look good to whoever's reading it: enough languages that it looks impressive, but not so many that they question whether it's possible or not.
I would only recommend doing this if you have sufficient programming experience and a firm enough grasp of fundamentals to be able to pick up new things quickly, however. Also, this assumes that you know enough about the language that you can discuss it intelligently.
I've found that playing skill-bingo usually results in lower quality potential employers anyway...at this point in my career, I'm looking for people who want to hire me because I can ship finished projects, whatever the language, and not because I know Java or C++ or Django or JQuery.
They don't need to know about how you know python, lisp, or whatever. In fact you are more than likely wasting their time. You literally get 10 to 20 seconds of time to shine in your resume - because thats the normal time it takes for a hiring manager to scan your resume. These people get a ton of resumes, so don't waste what little precious time you have.
"You only know a language when you know when not to use it"